F5-K000138477: High severity f5 big-ip next vulnerability
Published Aug 14, 2024
·Updated
When a TCP profile with Multipath TCP enabled (MPTCP) is configured on a virtual server, undisclosed traffic along with conditions beyond the attacker's control can cause the Traffic Management Microkernel (TMM) to terminate.
Affected Software
5 affected componentsFixes available
F5 BIG-IP Next SPK>=1.7.0<=1.8.2
1.9.0
F5 BIG-IP Next CNF>=1.1.0<=1.1.1
1.2.0
F5 BIG-IP=17.1.0
17.1.1
F5 BIG-IP>=16.1.0<=16.1.4
16.1.5
F5 BIG-IP>=15.1.0<=15.1.9
15.1.10
Event History
Aug 14, 2024
Advisory Published
via F5·01:16 PM
Frequently Asked Questions
1
What is the severity of F5-K000138477?
The severity of F5-K000138477 is considered high due to the potential for service disruption.
2
How do I fix F5-K000138477?
To fix F5-K000138477, update to the recommended versions detailed in the advisory.
3
What products are affected by F5-K000138477?
F5-K000138477 affects multiple versions of F5 BIG-IP and F5 BIG-IP Next products.
4
Can F5-K000138477 lead to system crashes?
Yes, F5-K000138477 can cause the Traffic Management Microkernel (TMM) to terminate unexpectedly.
5
Is there a workaround for F5-K000138477?
Currently, there is no documented workaround for F5-K000138477; updating to secure versions is recommended.