CVE-2019-6686: Medium severity riverbed steelapp traffic manager vulnerability
On BIG-IP versions 15.0.0-15.0.1.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, the Traffic Management Microkernel (TMM) might stop responding after the total number of diameter connections and pending messages on a single virtual server has reached 32K.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-6686?
CVE-2019-6686 has a critical severity rating due to the potential denial of service caused by the Traffic Management Microkernel becoming unresponsive.
Which BIG-IP versions are affected by CVE-2019-6686?
CVE-2019-6686 affects F5 BIG-IP Local Traffic Manager versions 15.0.0 to 15.0.1.1, 14.1.0 to 14.1.2, 14.0.0 to 14.0.1, and 13.1.0 to 13.1.3.1.
How do I fix CVE-2019-6686?
To remediate CVE-2019-6686, upgrade the affected F5 BIG-IP Local Traffic Manager to a version that is not within the specified ranges.
What impact does CVE-2019-6686 have on services?
CVE-2019-6686 can lead to service disruption as the Traffic Management Microkernel may stop responding when the limit of connections is exceeded.
Is there a workaround for CVE-2019-6686?
There are no documented workarounds for CVE-2019-6686, so upgrading to a patched version is recommended.