CVE-2017-6147: Medium severity F5 Big-ip Local Traffic Manager vulnerability
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe 12.1.2-HF1 and 13.0.0, an undisclosed type of responses may cause TMM to restart, causing an interruption of service when "SSL Forward Proxy" setting is enabled in both the Client and Server SSL profiles assigned to a BIG-IP Virtual Server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6147?
The severity of CVE-2017-6147 is considered to be high due to its potential to cause service interruption.
How do I fix CVE-2017-6147?
To fix CVE-2017-6147, update your F5 BIG-IP software to versions 12.1.2-HF2 or 13.0.0-HF1 or later.
Which F5 BIG-IP versions are affected by CVE-2017-6147?
CVE-2017-6147 affects F5 BIG-IP versions 12.1.2 and 13.0.0.
What does CVE-2017-6147 affect in F5 BIG-IP systems?
CVE-2017-6147 affects several modules including LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe.
What happens if I leave CVE-2017-6147 unpatched?
Leaving CVE-2017-6147 unpatched may lead to TMM restarts and service interruptions for users.