CVE-2018-15311
5.9
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.2 / Impact: 3.6
Source: NVD
Description
When F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.5, 11.6.0-11.6.3.2, or 11.5.1-11.5.6 is processing specially crafted TCP traffic with the Large Receive Offload (LRO) feature enabled, TMM may crash, leading to a failover event. This vulnerability is not exposed unless LRO is enabled, so most affected customers will be on 13.1.x. LRO has been available since 11.4.0 but is not enabled by default until 13.1.0.
Affected (52)
Products: F5: Big Ip Local Traffic Manager, Big Ip Application Acceleration Manager, Big Ip Advanced Firewall Manager, Big Ip Analytics, Big Ip Access Policy Manager, Big Ip Application Security Manager, Big Ip Domain Name System, Big Ip Edge Gateway, Big Ip Fraud Protection Service, Big Ip Global Traffic Manager, Big Ip Link Controller, Big Ip Policy Enforcement Manager, Big Ip Webaccelerator
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.1 to 11.5.6 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.1 to 11.5.6 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.1 to 11.5.6 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.1 to 11.5.6 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.1 to 11.5.6 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.1 to 11.5.6 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.1 to 11.5.6 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.1 to 11.5.6 |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.1 to 11.5.6 |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.1 to 11.5.6 |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.1 to 11.5.6 |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.1 to 11.5.6 |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.1 to 11.5.6 |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory
Timeline
No history available yet.