CVE-2017-6166
In BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe software 12.0.0 to 12.1.1, in some cases the Traffic Management Microkernel (TMM) may crash when processing fragmented packets. This vulnerability affects TMM through a virtual server configured with a FastL4 profile. Traffic processing is disrupted while TMM restarts. If the affected BIG-IP system is configured as part of a device group, it will trigger a failover to the peer device.
Published:Nov 22, 2017
Last Modified:Apr 20, 2025
EPS:Nov 22, 2017
EPSS Score:0.01202
CVSS Score:5.9
Affected Products
Vendor
Product
Action
Vendor
F5
Product
Big-ip Afm
F5
Big-ip Afm
Vendor
F5
Product
Big-ip Analytics
F5
Big-ip Analytics
Vendor
F5
Product
Big-ip Apm
F5
Big-ip Apm
Vendor
F5
Product
Big-ip Application Acceleration Manager
F5
Big-ip Application Acceleration Manager
Vendor
F5
Product
Big-ip Asm
F5
Big-ip Asm
Vendor
F5
Product
Big-ip Dns
F5
Big-ip Dns
Vendor
F5
Product
Big-ip Link Controller
F5
Big-ip Link Controller
Vendor
F5
Product
Big-ip Ltm
F5
Big-ip Ltm
Vendor
F5
Product
Big-ip Pem
F5
Big-ip Pem
Vendor
F5
Product
F5 Websafe
F5
F5 Websafe
Vendor
F5
Product
Linerate
F5
Linerate
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
