CVE-2015-7759: Input Validation
BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, Link Controller, and PEM 12.0.0 before HF1, when the TCP profile for a virtual server is configured with Congestion Metrics Cache enabled, allow remote attackers to cause a denial of service (Traffic Management Microkernel (TMM) restart) via crafted ICMP packets, related to Path MTU (PMTU) discovery.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7759?
CVE-2015-7759 has a high severity rating due to its potential to cause a denial of service by restarting the Traffic Management Microkernel.
How do I fix CVE-2015-7759?
To fix CVE-2015-7759, apply the latest hotfix for BIG-IP software version 12.0.0.
Which products are affected by CVE-2015-7759?
CVE-2015-7759 affects various F5 BIG-IP products including LTM, AAM, AFM, Analytics, APM, ASM, Link Controller, and PEM version 12.0.0 before HF1.
What impacts does CVE-2015-7759 have on my system?
CVE-2015-7759 allows remote attackers to disrupt services by causing the TMM to restart, leading to possible downtime.
How can I mitigate risks associated with CVE-2015-7759?
To mitigate risks from CVE-2015-7759, users should ensure they are running updated versions of affected software and implement network security measures to monitor ICMP traffic.