CVE-2017-6147
Last modified
CVE-2017-6147 is a vulnerability of currently unknown severity. In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe 12.1.2-HF1 and 13.0.0, an undisclosed type of responses may cause TMM to restart, causing an interruption of service when "SSL Forward Proxy" setting is enabled in both the Client and Server SSL profiles assigned to a BIG-IP Virtual Server.. EPSS estimates a 1.33% chance of exploitation in the next 30 days.
Description
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe 12.1.2-HF1 and 13.0.0, an undisclosed type of responses may cause TMM to restart, causing an interruption of service when "SSL Forward Proxy" setting is enabled in both the Client and Server SSL profiles assigned to a BIG-IP Virtual Server.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| F5 | Big-Ip Local Traffic Manager | 12.1.2 |
| F5 | Big-Ip Local Traffic Manager | 13.0.0 |
| F5 | Big-Ip Application Acceleration Manager | 12.1.2 |
| F5 | Big-Ip Application Acceleration Manager | 13.0.0 |
| F5 | Big-Ip Advanced Firewall Manager | 12.1.2 |
| F5 | Big-Ip Advanced Firewall Manager | 13.0.0 |
| F5 | Big-Ip Analytics | 12.1.2 |
| F5 | Big-Ip Analytics | 13.0.0 |
| F5 | Big-Ip Access Policy Manager | 12.1.2 |
| F5 | Big-Ip Access Policy Manager | 13.0.0 |
| F5 | Big-Ip Application Security Manager | 12.1.2 |
| F5 | Big-Ip Application Security Manager | 13.0.0 |
| F5 | Big-Ip Domain Name System | 12.1.2 |
| F5 | Big-Ip Domain Name System | 13.0.0 |
| F5 | Big-Ip Link Controller | 12.1.2 |
| F5 | Big-Ip Link Controller | 13.0.0 |
| F5 | Big-Ip Policy Enforcement Manager | 12.1.2 |
| F5 | Big-Ip Policy Enforcement Manager | 13.0.0 |
| F5 | Big-Ip Websafe | 12.1.2 |
| F5 | Big-Ip Websafe | 13.0.0 |
References
- http://www.securityfocus.com/bid/100981Third Party Advisory, VDB Entry
- https://support.f5.com/csp/article/K43945001Vendor Advisory
- http://www.securityfocus.com/bid/100981Third Party Advisory, VDB Entry
- https://support.f5.com/csp/article/K43945001Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-6147?
How severe is CVE-2017-6147?
How do I fix CVE-2017-6147?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-6141In F5 BIG-IP LTM, AAM, AFM, APM, ASM, Link Controller, PEM, …
- CVE-2017-6142X509 certificate verification was not correctly implemented …
- CVE-2017-6143X509 certificate verification was not correctly implemented …
- CVE-2017-6144In F5 BIG-IP PEM 12.1.0 through 12.1.2 when downloading the …
- CVE-2017-6145iControl REST in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, AS…
- CVE-2017-6146Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2017-6148Responses to SOCKS proxy requests made through F5 BIG-IP ver…
- CVE-2017-6149Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2017-6150Under certain conditions for F5 BIG-IP systems 13.0.0 or 12.…
- CVE-2017-6151In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge G…
- CVE-2017-6152A local user on F5 BIG-IQ Centralized Management 5.1.0-5.2.0…
- CVE-2017-6153Features in F5 BIG-IP 13.0.0-13.1.0.3, 12.1.0-12.1.3.1, 11.6…
Are you affected by CVE-2017-6147?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
