{"id": "CVE-2017-6159", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "
[email protected]", "cvssData": {"version": "2.0", "baseScore": 4.3, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:N/C:N/I:N/A:P", "authentication": "NONE", "integrityImpact": "NONE", "accessComplexity": "MEDIUM", "availabilityImpact": "PARTIAL", "confidentialityImpact": "NONE"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 8.6, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV30": [{"type": "Primary", "source": "
[email protected]", "cvssData": {"scope": "UNCHANGED", "version": "3.0", "baseScore": 5.9, "attackVector": "NETWORK", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "integrityImpact": "NONE", "userInteraction": "NONE", "attackComplexity": "HIGH", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "NONE"}, "impactScore": 3.6, "exploitabilityScore": 2.2}]}, "published": "2017-10-27T14:29:00.310", "references": [{"url": "http://www.securityfocus.com/bid/101633", "tags": ["Third Party Advisory", "VDB Entry"], "source": "
[email protected]"}, {"url": "http://www.securitytracker.com/id/1039669", "tags": ["Third Party Advisory", "VDB Entry"], "source": "
[email protected]"}, {"url": "https://support.f5.com/csp/article/K10002335", "tags": ["Vendor Advisory"], "source": "
[email protected]"}, {"url": "http://www.securityfocus.com/bid/101633", "tags": ["Third Party Advisory", "VDB Entry"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securitytracker.com/id/1039669", "tags": ["Third Party Advisory", "VDB Entry"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://support.f5.com/csp/article/K10002335", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Deferred", "weaknesses": [{"type": "Primary", "source": "
[email protected]", "description": [{"lang": "en", "value": "NVD-CWE-noinfo"}]}], "descriptions": [{"lang": "en", "value": "F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM, Websafe software version 12.0.0 to 12.1.2, 11.6.0 to 11.6.1 are vulnerable to a denial of service attack when the MPTCP option is enabled on a virtual server. Data plane is vulnerable when using the MPTCP option of a TCP profile. There is no control plane exposure. An attacker may be able to disrupt services by causing TMM to restart hence temporarily failing to process traffic."}, {"lang": "es", "value": "F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM, Websafe en sus versiones de software de la 12.0.0 a la 12.1.2 y de la 11.6.0 a la 11.6.1 son vulnerables a un ataque de denegaci\u00f3n de servicio (DoS) cuando la opci\u00f3n MPTCP est\u00e1 habilitada en un servidor virtual. El plano de datos es vulnerable cuando se utiliza la opci\u00f3n MPTCP de un perfil TCP. No hay ninguna exposici\u00f3n del plano de control. Un atacante podr\u00eda interrumpir los servicios haciendo que el TMM se reinicie, haciendo que no se pueda procesar el tr\u00e1fico temporalmente."}], "lastModified": "2025-04-20T01:37:25.860", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:f5:big-ip_local_traffic_manager:11.6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2FF5A5F6-4BA3-4276-8679-B5560EACF2E0"}, {"criteria": "cpe:2.3:a:f5:big-ip_local_traffic_manager:11.6.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A2B502F2-404C-463B-B6BE-87489DC881F9"}, {"criteria": "cpe:2.3:a:f5:big-ip_local_traffic_manager:12.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "44F1E5E0-BD63-4A4A-BC4E-A1D5495F8B5C"}, {"criteria": "cpe:2.3:a:f5:big-ip_local_traffic_manager:12.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A82C7B1C-E195-4D94-B604-78FB464C4F81"}, {"criteria": "cpe:2.3:a:f5:big-ip_local_traffic_manager:12.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8F6C3144-D0DE-4248-BFCD-04A7E6104044"}, {"criteria": "cpe:2.3:a:f5:big-ip_local_traffic_manager:12.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0357B5ED-0600-4756-93E5-692987068596"}], "operator": "OR"}]}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:f5:big-ip_application_acceleration_manager:11.6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E5B40837-EC2B-41FB-ACC3-806054EAF28C"}, {"criteria": "cpe:2.3:a:f5:big-ip_application_acceleration_manager:11.6.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "48BE0210-7058-462A-BA17-845D3E4F52FA"}, {"criteria": "cpe:2.3:a:f5:big-ip_application_acceleration_manager:12.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3CA2FA6B-3930-432F-8FB5-E73604CEFE42"}, {"criteria": "cpe:2.3:a:f5:big-ip_application_acceleration_manager:12.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "ECA90FB8-E2CD-400F-B753-1B482E7FAC96"}, {"criteria": "cpe:2.3:a:f5:big-ip_application_acceleration_manager:12.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6FEC804B-35DB-4A0C-9AEA-15527E0CC1B1"}, {"criteria": "cpe:2.3:a:f5:big-ip_application_acceleration_manager:12.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BEB228A9-0C01-4531-B2B2-38BB7B0E02E9"}], "operator": "OR"}]}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:f5:big-ip_advanced_firewall_manager:11.6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B276E4DF-69FC-4158-B93A-781A45605034"}, {"criteria": "cpe:2.3:a:f5:big-ip_advanced_firewall_manager:11.6.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CBAB92C5-2D50-49CC-AECA-0D16BC44A788"}, {"criteria": "cpe:2.3:a:f5:big-ip_advanced_firewall_manager:12.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "532AAF54-64EF-4852-B4F1-D5E660463704"}, {"criteria": "cpe:2.3:a:f5:big-ip_advanced_firewall_manager:12.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BC827031-CA39-4081-8CE0-30EAC78DF756"}, {"criteria": "cpe:2.3:a:f5:big-ip_advanced_firewall_manager:12.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7569903B-3A15-4A10-863B-6828337DD268"}, {"criteria": "cpe:2.3:a:f5:big-ip_advanced_firewall_manager:12.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "45825991-D17D-42F1-87B4-7DF86B098B45"}], "operator": "OR"}]}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:f5:big-ip_access_policy_manager:11.6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CFA77C6B-72DB-4D57-87CF-11F2C7EDB828"}, {"criteria": "cpe:2.3:a:f5:big-ip_access_policy_manager:11.6.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E33BCA5B-CE91-451C-9821-2023A9E461C1"}, {"criteria": "cpe:2.3:a:f5:big-ip_access_policy_manager:12.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3B62FEC0-EE22-46E6-B811-8AB0EE4C3E2E"}, {"criteria": "cpe:2.3:a:f5:big-ip_access_policy_manager:12.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FCD2044C-AC6F-4145-B1A0-8EB26DCF1F8C"}, {"criteria": "cpe:2.3:a:f5:big-ip_access_policy_manager:12.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5FC866D4-CE8C-4408-AD1E-8643AC554CC9"}, {"criteria": "cpe:2.3:a:f5:big-ip_access_policy_manager:12.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7563D979-BE37-4251-B92E-0DBDBE53F3FF"}], "operator": "OR"}]}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:f5:big-ip_application_security_manager:11.6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "475F0EF8-42CB-4099-9C4A-390F946C4924"}, {"criteria": "cpe:2.3:a:f5:big-ip_application_security_manager:11.6.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "94DBCD7A-E4DA-4C08-87A4-960CF53A83E6"}, {"criteria": "cpe:2.3:a:f5:big-ip_application_security_manager:12.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "62B0A70A-D101-443E-A543-5EC35E23D66F"}, {"criteria": "cpe:2.3:a:f5:big-ip_application_security_manager:12.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2DB2118A-0F9C-4273-BB07-85FEA32C785B"}, {"criteria": "cpe:2.3:a:f5:big-ip_application_security_manager:12.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8541C9EF-69A8-4641-B173-3BCE0EDD20A8"}, {"criteria": "cpe:2.3:a:f5:big-ip_application_security_manager:12.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E24A3C71-0075-4738-B114-267337D050CD"}], "operator": "OR"}]}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:f5:big-ip_link_controller:11.6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5CDEC701-DAB3-4D92-AA67-B886E6693E46"}, {"criteria": "cpe:2.3:a:f5:big-ip_link_controller:11.6.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8C641B4F-DCFF-4A1B-9E00-EDF18A270241"}, {"criteria": "cpe:2.3:a:f5:big-ip_link_controller:12.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E90C12AF-44BA-44A2-89ED-0C2497EEC8A6"}, {"criteria": "cpe:2.3:a:f5:big-ip_link_controller:12.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BBBB6E7C-DA1A-479F-9DD2-DE0C3CA82E92"}, {"criteria": "cpe:2.3:a:f5:big-ip_link_controller:12.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4913B437-33FF-4B5E-A855-9DA00B35E3B3"}, {"criteria": "cpe:2.3:a:f5:big-ip_link_controller:12.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EDCFE65B-340B-4F7D-93A1-4390BBC8E67F"}], "operator": "OR"}]}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:f5:big-ip_policy_enforcement_manager:11.6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CB8D3B87-B8F5-490A-B1D9-04F2EE93EEA3"}, {"criteria": "cpe:2.3:a:f5:big-ip_policy_enforcement_manager:11.6.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C1EA4F45-35F7-4687-8D1A-A5ACD846500A"}, {"criteria": "cpe:2.3:a:f5:big-ip_policy_enforcement_manager:12.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "23FF9627-E561-4CF7-A685-6E33D2F6C98C"}, {"criteria": "cpe:2.3:a:f5:big-ip_policy_enforcement_manager:12.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "64273A2C-E5A1-4605-92DD-EBECC7F051D5"}, {"criteria": "cpe:2.3:a:f5:big-ip_policy_enforcement_manager:12.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E60CA151-1C3A-45B3-B939-E6F80063C595"}, {"criteria": "cpe:2.3:a:f5:big-ip_policy_enforcement_manager:12.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "58BAD5A9-9C67-4056-9344-07C8C42C8E88"}], "operator": "OR"}]}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:f5:big-ip_websafe:1.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9E6556BF-A50D-4872-BF81-9397A7ECEC9C"}], "operator": "OR"}]}], "sourceIdentifier": "
[email protected]"}