CVE-2024-24775: BIG-IP TMM vulnerability
When a virtual server is enabled with VLAN group and SNAT listener is configured, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
F5 BIG-IP and BIG-IQ Centralized Managementto a version that resolves this vulnerability.Fixed in 17.1.1 - Upgrade
Upgrade
F5 BIG-IP and BIG-IQ Centralized Managementto a version that resolves this vulnerability.Fixed in 16.1.4 - Upgrade
Upgrade
F5 BIG-IP and BIG-IQ Centralized Managementto a version that resolves this vulnerability.Fixed in 15.1.10
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24775?
The severity of CVE-2024-24775 is currently not disclosed, but it may impact the availability of the affected systems.
How do I fix CVE-2024-24775?
To resolve CVE-2024-24775, you must upgrade your F5 BIG-IP devices to a fixed version listed in the remedy section of the vulnerability details.
Which F5 BIG-IP versions are affected by CVE-2024-24775?
CVE-2024-24775 affects F5 BIG-IP versions 15.1.0 to 15.1.9, 16.1.0 to 16.1.4, and 17.1.0.
What products are impacted by CVE-2024-24775?
Products impacted by CVE-2024-24775 include F5 BIG-IP, BIG-IP Access Policy Manager, and BIG-IP Advanced Firewall Manager among others.
What type of issue is CVE-2024-24775?
CVE-2024-24775 is a vulnerability that can lead to the termination of the Traffic Management Microkernel (TMM) due to undisclosed traffic.