F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM, Websafe software version 12.0.0 to 12.1.2, 11.6.0 to 11.6.1 are vulnerable to a denial of service attack when the MPTCP option is enabled on a virtual server. Data plane is vulnerable when using the MPTCP option of a TCP profile. There is no control plane exposure. An attacker may be able to disrupt services by causing TMM to restart hence temporarily failing to process traffic.
References
Link Resource
http://www.securityfocus.com/bid/101633 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1039669 Third Party Advisory VDB Entry
https://support.f5.com/csp/article/K10002335 Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: f5

Published: 2017-10-26T00:00:00

Updated: 2017-11-02T09:57:01

Reserved: 2017-02-21T00:00:00


Link: CVE-2017-6159

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2017-10-27T14:29:00.310

Modified: 2019-10-03T00:03:26.223


Link: CVE-2017-6159

JSON object: View

cve-icon Redhat Information

No data.