CVE-2017-6161
5.3
Vector
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 1.6 / Impact: 3.6
Source: NVD
Description
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, WebAccelerator software version 12.0.0 - 12.1.2, 11.6.0 - 11.6.1, 11.4.0 - 11.5.4, 11.2.1, when ConfigSync is configured, attackers on adjacent networks may be able to bypass the TLS protections usually used to encrypted and authenticate connections to mcpd. This vulnerability may allow remote attackers to cause a denial-of-service (DoS) attack via resource exhaustion.
Affected (109)
Products: F5: Big Ip Local Traffic Manager, Big Ip Application Acceleration Manager, Big Ip Advanced Firewall Manager, Big Ip Access Policy Manager, Big Ip Application Security Manager, Big Ip Link Controller, Big Ip Policy Enforcement Manager, Big Ip Domain Name System, Big Ip Edge Gateway, Big Ip Global Traffic Manager, Big Ip Webaccelerator
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.0 to 11.5.4 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.0 to 11.5.4 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.0 to 11.5.4 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.0 to 11.5.4 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.0 to 11.5.4 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.0 to 11.5.4 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.0 to 11.5.4 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.4.0 to 11.5.4 |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.2.1 |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.2.1 |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.2.1 |
References (8)
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.