CVE-2019-6671: High severity f5 access policy manager vulnerability
On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, and 13.1.0-13.1.3.1, under certain conditions tmm may leak memory when processing packet fragments, leading to resource starvation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-6671?
CVE-2019-6671 is considered a medium severity vulnerability due to the potential for resource starvation caused by memory leakage in affected BIG-IP versions.
How do I fix CVE-2019-6671?
To fix CVE-2019-6671, it is recommended to upgrade to a version of BIG-IP that is not affected, specifically versions later than 15.0.1, 14.1.2, 14.0.1, or 13.1.3.1.
Which versions of F5 BIG-IP are affected by CVE-2019-6671?
CVE-2019-6671 affects F5 BIG-IP versions 15.0.0 to 15.0.1, 14.1.0 to 14.1.2, 14.0.0 to 14.0.1, and 13.1.0 to 13.1.3.1.
What are potential consequences of CVE-2019-6671 exploitation?
Exploitation of CVE-2019-6671 can lead to resource starvation, impacting the performance and availability of services managed by affected BIG-IP devices.
Is there a workaround for CVE-2019-6671?
Currently, the most effective mitigation for CVE-2019-6671 is to upgrade to a non-vulnerable version of the F5 BIG-IP software.