CVE-2017-6147
Last modified
CVE-2017-6147 is a vulnerability of currently unknown severity. In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe 12.1.2-HF1 and 13.0.0, an undisclosed type of responses may cause TMM to restart, causing an interruption of service when "SSL Forward Proxy" setting is enabled in both the Client and Server SSL profiles assigned to a BIG-IP Virtual Server.. EPSS estimates a 1.33% chance of exploitation in the next 30 days.
Description
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe 12.1.2-HF1 and 13.0.0, an undisclosed type of responses may cause TMM to restart, causing an interruption of service when "SSL Forward Proxy" setting is enabled in both the Client and Server SSL profiles assigned to a BIG-IP Virtual Server.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| F5 | Big-Ip Local Traffic Manager | 12.1.2 |
| F5 | Big-Ip Local Traffic Manager | 13.0.0 |
| F5 | Big-Ip Application Acceleration Manager | 12.1.2 |
| F5 | Big-Ip Application Acceleration Manager | 13.0.0 |
| F5 | Big-Ip Advanced Firewall Manager | 12.1.2 |
| F5 | Big-Ip Advanced Firewall Manager | 13.0.0 |
| F5 | Big-Ip Analytics | 12.1.2 |
| F5 | Big-Ip Analytics | 13.0.0 |
| F5 | Big-Ip Access Policy Manager | 12.1.2 |
| F5 | Big-Ip Access Policy Manager | 13.0.0 |
| F5 | Big-Ip Application Security Manager | 12.1.2 |
| F5 | Big-Ip Application Security Manager | 13.0.0 |
| F5 | Big-Ip Domain Name System | 12.1.2 |
| F5 | Big-Ip Domain Name System | 13.0.0 |
| F5 | Big-Ip Link Controller | 12.1.2 |
| F5 | Big-Ip Link Controller | 13.0.0 |
| F5 | Big-Ip Policy Enforcement Manager | 12.1.2 |
| F5 | Big-Ip Policy Enforcement Manager | 13.0.0 |
| F5 | Big-Ip Websafe | 12.1.2 |
| F5 | Big-Ip Websafe | 13.0.0 |
References
- http://www.securityfocus.com/bid/100981Third Party Advisory, VDB Entry
- https://support.f5.com/csp/article/K43945001Vendor Advisory
- http://www.securityfocus.com/bid/100981Third Party Advisory, VDB Entry
- https://support.f5.com/csp/article/K43945001Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-6147?
How severe is CVE-2017-6147?
How do I fix CVE-2017-6147?
Are you affected by CVE-2017-6147?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
