CVE-2024-41727
8.7
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow more
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: f5sirt@f5.com (Secondary)
Description
In BIG-IP tenants running on r2000 and r4000 series hardware, or BIG-IP Virtual Edition (VEs) using Intel E810 SR-IOV NIC, undisclosed traffic can cause an increase in memory resource utilization.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected (63)
Products: F5: Big Ip Access Policy Manager, Big Ip Advanced Firewall Manager, Big Ip Advanced Web Application Firewall, Big Ip Analytics, Big Ip Application Acceleration Manager, Big Ip Application Security Manager, Big Ip Application Visibility And Reporting, Big Ip Automation Toolchain, Big Ip Carrier Grade Nat, Big Ip Container Ingress Services, Big Ip Ddos Hybrid Defender, Big Ip Domain Name System, Big Ip Edge Gateway, Big Ip Fraud Protection Service, Big Ip Global Traffic Manager, Big Ip Link Controller, Big Ip Local Traffic Manager, Big Ip Policy Enforcement Manager, Big Ip Ssl Orchestrator, Big Ip Webaccelerator, Big Ip Websafe
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 15.1.0 to 15.1.1 | |
| From 15.1.0 to 15.1.1 | |
| From 15.1.0 to 15.1.1 | |
| From 15.1.0 to 15.1.1 | |
| From 15.1.0 to 15.1.1 | |
| From 15.1.0 to 15.1.1 | |
| From 15.1.0 to 15.1.1 | |
| From 15.1.0 to 15.1.1 | |
| From 15.1.0 to 15.1.1 | |
| From 15.1.0 to 15.1.1 | |
| From 15.1.0 to 15.1.1 | |
| From 15.1.0 to 15.1.1 | |
| From 15.1.0 to 15.1.1 | |
| From 15.1.0 to 15.1.1 | |
| From 15.1.0 to 15.1.1 | |
| From 15.1.0 to 15.1.1 | |
| From 15.1.0 to 15.1.1 | |
| From 15.1.0 to 15.1.1 | |
| From 15.1.0 to 15.1.1 | |
| From 15.1.0 to 15.1.1 | |
| From 15.1.0 to 15.1.1 |
| Running on/with | Platform Versions |
|---|---|
F5 R2000 | All versions |
F5 R4000 | All versions |
Related CWEs
CWE-400
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CWE-770
Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.
References (1)
Timeline
No history available yet.