CVE-2015-5058

UnknownEPSS 1.91%

Last modified

CVE-2015-5058 is a vulnerability of currently unknown severity. Memory leak in the virtual server component in F5 Big-IP LTM, AAM, AFM, Analytics, APM, ASM, GTM, Link Controller, and PEM 11.5.x before 11.5.1 HF10, 11.5.3 before HF1, and 11.6.0 before HF5, BIG-IQ Cloud, Device, and Security 4.4.0 through 4.5.0, and BIG-IQ ADC 4.5.0 allows remote attackers to cause a denial of service (memory consumption) via a large number of crafted ICMP packets.. EPSS estimates a 1.91% chance of exploitation in the next 30 days.

Description

Memory leak in the virtual server component in F5 Big-IP LTM, AAM, AFM, Analytics, APM, ASM, GTM, Link Controller, and PEM 11.5.x before 11.5.1 HF10, 11.5.3 before HF1, and 11.6.0 before HF5, BIG-IQ Cloud, Device, and Security 4.4.0 through 4.5.0, and BIG-IQ ADC 4.5.0 allows remote attackers to cause a denial of service (memory consumption) via a large number of crafted ICMP packets.

Metrics

EPSS Probability
1.91%

77.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
F5Big-Ip Access Policy Manager11.5.1
F5Big-Ip Access Policy Manager11.5.3
F5Big-Ip Access Policy Manager11.6.0
F5Big-Ip Advanced Firewall Manager11.5.1
F5Big-Ip Advanced Firewall Manager11.5.3
F5Big-Ip Advanced Firewall Manager11.6.0
F5Big-Ip Analytics11.5.1
F5Big-Ip Analytics11.5.3
F5Big-Ip Analytics11.6.0
F5Big-Ip Application Acceleration Manager11.5.1
F5Big-Ip Application Acceleration Manager11.5.3
F5Big-Ip Application Acceleration Manager11.6.0
F5Big-Ip Application Security Manager11.5.1
F5Big-Ip Application Security Manager11.5.3
F5Big-Ip Application Security Manager11.6.0
F5Big-Ip Global Traffic Manager11.5.1
F5Big-Ip Global Traffic Manager11.5.3
F5Big-Ip Global Traffic Manager11.6.0
F5Big-Ip Link Controller11.5.1
F5Big-Ip Link Controller11.5.3
F5Big-Ip Link Controller11.6.0
F5Big-Ip Local Traffic Manager11.5.1
F5Big-Ip Local Traffic Manager11.5.3
F5Big-Ip Local Traffic Manager11.6.0
F5Big-Iq Adc4.5.0
F5Big-Iq Cloud4.4.0
F5Big-Iq Cloud4.5.0
F5Big-Iq Device4.4.0
F5Big-Iq Device4.5.0
F5Big-Iq Security4.4.0
F5Big-Iq Security4.5.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2015-5058?
Memory leak in the virtual server component in F5 Big-IP LTM, AAM, AFM, Analytics, APM, ASM, GTM, Link Controller, and PEM 11.5.x before 11.5.1 HF10, 11.5.3 before HF1, and 11.6.0 before HF5, BIG-IQ Cloud, Device, and Security 4.4.0 through 4.5.0, and BIG-IQ ADC 4.5.0 allows remote attackers to cause a denial of service (memory consumption) via a large number of crafted ICMP packets.
How severe is CVE-2015-5058?
Severity scoring for CVE-2015-5058 is pending analysis. The EPSS model estimates a 1.91% probability of exploitation in the next 30 days.
How do I fix CVE-2015-5058?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2015-5058?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST