CVE-2015-4638: Input Validation
The FastL4 virtual server in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, GTM, Link Controller, and PEM 11.3.0 through 11.5.2 and 11.6.0 through 11.6.0 HF4, BIG-IP Edge Gateway, WebAccelerator, and WOM 11.2.1 through 11.3.0, and BIG-IP PSM 11.2.1 through 11.4.1 allows remote attackers to cause a denial of service (Traffic Management Microkernel restart) via a fragmented packet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4638?
CVE-2015-4638 is classified as a high-severity vulnerability due to its potential for remote exploitation.
How do I fix CVE-2015-4638?
To fix CVE-2015-4638, upgrade affected F5 BIG-IP software to versions that contain the necessary security patches.
What products are affected by CVE-2015-4638?
CVE-2015-4638 affects multiple products including F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, GTM, and others in specified versions.
Can CVE-2015-4638 be exploited remotely?
Yes, CVE-2015-4638 can be exploited remotely by attackers, potentially leading to serious security breaches.
Is there a workaround for CVE-2015-4638 if I cannot update immediately?
There are no effective workarounds documented for CVE-2015-4638, making it crucial to apply updates as soon as feasible.