CVE-2016-7468: Medium severity riverbed steelapp traffic manager vulnerability
An unauthenticated remote attacker may be able to disrupt services on F5 BIG-IP 11.4.1 - 11.5.4 devices with maliciously crafted network traffic. This vulnerability affects virtual servers associated with TCP profiles when the BIG-IP system's tm.tcpprogressive db variable value is set to non-default setting "enabled". The default value for the tm.tcpprogressive db variable is "negotiate". An attacker may be able to disrupt traffic or cause the BIG-IP system to fail over to another device in the device group.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-7468?
CVE-2016-7468 has a high severity due to its potential to allow unauthenticated remote attackers to disrupt services.
How do I fix CVE-2016-7468?
To fix CVE-2016-7468, apply the recommended updates provided by F5 for the affected BIG-IP versions.
Which versions of F5 BIG-IP are affected by CVE-2016-7468?
CVE-2016-7468 affects F5 BIG-IP versions 11.4.1 to 11.5.4.
What are the potential impacts of CVE-2016-7468?
The potential impacts of CVE-2016-7468 include service disruptions for virtual servers associated with TCP profiles.
Is user authentication required to exploit CVE-2016-7468?
No, CVE-2016-7468 can be exploited by unauthenticated remote attackers.