CVE-2016-5024: Input Validation
Virtual servers in F5 BIG-IP systems 11.6.1 before 11.6.1 HF1 and 12.1.x before 12.1.2, when configured to parse RADIUS messages via an iRule, allow remote attackers to cause a denial of service (Traffic Management Microkernel restart) via crafted network traffic.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5024?
CVE-2016-5024 is rated as a high severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2016-5024?
To fix CVE-2016-5024, upgrade your F5 BIG-IP system to a version that is 11.6.1 HF1 or later, or 12.1.2 or later.
What systems are affected by CVE-2016-5024?
CVE-2016-5024 affects F5 BIG-IP systems 11.6.1 before HF1 and 12.1.x before 12.1.2 that are configured to parse RADIUS messages via an iRule.
What type of attacks can CVE-2016-5024 enable?
CVE-2016-5024 can enable remote attackers to cause a denial of service through crafted network traffic.
What components of F5 BIG-IP are impacted by CVE-2016-5024?
CVE-2016-5024 impacts various components including Local Traffic Manager, Application Security Manager, and Access Policy Manager, among others.