CVE-2017-6157: High severity riverbed steelapp traffic manager vulnerability
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and Websafe software version 12.0.0 to 12.1.1, 11.6.0 to 11.6.1, 11.5.0 - 11.5.4, virtual servers with a configuration using the HTTP Explicit Proxy functionality and/or SOCKS profile are vulnerable to an unauthenticated, remote attack that allows modification of BIG-IP system configuration, extraction of sensitive system files, and/or possible remote command execution on the BIG-IP system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6157?
CVE-2017-6157 has been classified as a high-severity vulnerability.
How do I fix CVE-2017-6157?
To fix CVE-2017-6157, you should upgrade affected F5 BIG-IP software versions to the latest available versions provided by F5 Networks.
Which F5 BIG-IP versions are affected by CVE-2017-6157?
CVE-2017-6157 affects F5 BIG-IP versions 11.5.0 to 11.5.4, 11.6.0, 11.6.1, as well as 12.0.0 to 12.1.1.
What components of F5 BIG-IP are vulnerable in CVE-2017-6157?
CVE-2017-6157 affects multiple components including LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM, and Websafe.
Is CVE-2017-6157 an authenticated vulnerability?
CVE-2017-6157 is an unauthenticated vulnerability, allowing attackers to exploit it without needing credentials.