CVE-2017-6159: Medium severity F5 Big-ip Local Traffic Manager vulnerability
F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM, Websafe software version 12.0.0 to 12.1.2, 11.6.0 to 11.6.1 are vulnerable to a denial of service attack when the MPTCP option is enabled on a virtual server. Data plane is vulnerable when using the MPTCP option of a TCP profile. There is no control plane exposure. An attacker may be able to disrupt services by causing TMM to restart hence temporarily failing to process traffic.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6159?
CVE-2017-6159 has been classified as a denial-of-service vulnerability with potential significant impact.
How do I fix CVE-2017-6159?
To mitigate CVE-2017-6159, disable the MPTCP option on affected F5 BIG-IP products.
What versions are affected by CVE-2017-6159?
CVE-2017-6159 affects F5 BIG-IP versions 11.6.0 to 11.6.1 and 12.0.0 to 12.1.2.
Can CVE-2017-6159 be exploited remotely?
Yes, CVE-2017-6159 can be exploited remotely, making it a high-risk vulnerability.
What products are affected by CVE-2017-6159?
CVE-2017-6159 impacts multiple F5 products including BIG-IP LTM, AAM, AFM, APM, and others.