F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM, Websafe software version 12.0.0 to 12.1.2, 11.6.0 to 11.6.1 are vulnerable to a denial of service attack when the MPTCP option is enabled on a virtual server. Data plane is vulnerable when using the MPTCP option of a TCP profile. There is no control plane exposure. An attacker may be able to disrupt services by causing TMM to restart hence temporarily failing to process traffic.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: f5

Published: 2017-10-27T14:00:00Z

Updated: 2024-09-17T02:46:34.159Z

Reserved: 2017-02-21T00:00:00

Link: CVE-2017-6159

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2017-10-27T14:29:00.310

Modified: 2019-10-03T00:03:26.223

Link: CVE-2017-6159

cve-icon Redhat

No data.