CVE-2017-6160

UnknownEPSS 3.65%

Last modified

CVE-2017-6160 is a vulnerability of currently unknown severity. In F5 BIG-IP AAM and PEM software version 12.0.0 to 12.1.1, 11.6.0 to 11.6.1, 11.4.1 to 11.5.4, a remote attacker may create maliciously crafted HTTP request to cause Traffic Management Microkernel (TMM) to restart and temporarily fail to process traffic. This issue is exposed on virtual servers using a Policy Enforcement profile or a Web Acceleration profile. EPSS estimates a 3.65% chance of exploitation in the next 30 days.

Description

In F5 BIG-IP AAM and PEM software version 12.0.0 to 12.1.1, 11.6.0 to 11.6.1, 11.4.1 to 11.5.4, a remote attacker may create maliciously crafted HTTP request to cause Traffic Management Microkernel (TMM) to restart and temporarily fail to process traffic. This issue is exposed on virtual servers using a Policy Enforcement profile or a Web Acceleration profile. Systems that do not have BIG-IP AAM module provisioned are not vulnerable. The Traffic Management Microkernel (TMM) may restart and temporarily fail to process traffic. Systems that do not have BIG-IP AAM or PEM module provisioned are not vulnerable.

Metrics

EPSS Probability
3.65%

88.2th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
F5Big-Ip Application Acceleration Manager11.4.0
F5Big-Ip Application Acceleration Manager11.4.1
F5Big-Ip Application Acceleration Manager11.5.0
F5Big-Ip Application Acceleration Manager11.5.1
F5Big-Ip Application Acceleration Manager11.5.2
F5Big-Ip Application Acceleration Manager11.5.3
F5Big-Ip Application Acceleration Manager11.5.4
F5Big-Ip Application Acceleration Manager11.5.5
F5Big-Ip Application Acceleration Manager11.6.0
F5Big-Ip Application Acceleration Manager11.6.1
F5Big-Ip Application Acceleration Manager12.0.0
F5Big-Ip Application Acceleration Manager12.1.0
F5Big-Ip Application Acceleration Manager12.1.1
F5Big-Ip Policy Enforcement Manager11.4.0
F5Big-Ip Policy Enforcement Manager11.4.1
F5Big-Ip Policy Enforcement Manager11.5.0
F5Big-Ip Policy Enforcement Manager11.5.1
F5Big-Ip Policy Enforcement Manager11.5.2
F5Big-Ip Policy Enforcement Manager11.5.3
F5Big-Ip Policy Enforcement Manager11.5.4
F5Big-Ip Policy Enforcement Manager11.5.5
F5Big-Ip Policy Enforcement Manager11.6.0
F5Big-Ip Policy Enforcement Manager11.6.1
F5Big-Ip Policy Enforcement Manager12.0.0
F5Big-Ip Policy Enforcement Manager12.1.0
F5Big-Ip Policy Enforcement Manager12.1.1

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2017-6160?
In F5 BIG-IP AAM and PEM software version 12.0.0 to 12.1.1, 11.6.0 to 11.6.1, 11.4.1 to 11.5.4, a remote attacker may create maliciously crafted HTTP request to cause Traffic Management Microkernel (TMM) to restart and temporarily fail to process traffic. This issue is exposed on virtual servers using a Policy Enforcement profile or a Web Acceleration profile. Systems that do not have BIG-IP AAM module provisioned are not vulnerable. The Traffic Management Microkernel (TMM) may restart and temporarily fail to process traffic. Systems that do not have BIG-IP AAM or PEM module provisioned are not vulnerable.
How severe is CVE-2017-6160?
Severity scoring for CVE-2017-6160 is pending analysis. The EPSS model estimates a 3.65% probability of exploitation in the next 30 days.
How do I fix CVE-2017-6160?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2017-6160?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST