First published: Mon Dec 23 2019(Updated: )
On BIG-IP versions 15.0.0-15.0.1.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, and 12.1.0-12.1.5, a memory leak in Multicast Forwarding Cache (MFC) handling in tmrouted.
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
Riverbed SteelApp Traffic Manager | >=12.1.0<=12.1.5 | |
Riverbed SteelApp Traffic Manager | >=13.1.0<13.1.3.2 | |
Riverbed SteelApp Traffic Manager | >=14.0.0<14.0.1.1 | |
Riverbed SteelApp Traffic Manager | >=14.1.0<14.1.2.1 | |
Riverbed SteelApp Traffic Manager | >=15.0.0<15.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-6681 has a severity rating of high due to the potential impact of a memory leak in the multicast forwarding cache.
To fix CVE-2019-6681, upgrade to one of the patched versions of BIG-IP specified in the vendor's advisory.
CVE-2019-6681 affects F5 BIG-IP Local Traffic Manager versions 12.1.0-12.1.5, 13.1.0-13.1.3.1, 14.0.0-14.1.2, and 15.0.0-15.0.1.1.
The impact of CVE-2019-6681 includes a potential service disruption due to memory exhaustion if the memory leak is exploited.
Yes, CVE-2019-6681 can potentially be exploited remotely, making it critical to apply fixes promptly.