Description
In F5 BIG-IP AAM and PEM software version 12.0.0 to 12.1.1, 11.6.0 to 11.6.1, 11.4.1 to 11.5.4, a remote attacker may create maliciously crafted HTTP request to cause Traffic Management Microkernel (TMM) to restart and temporarily fail to process traffic. This issue is exposed on virtual servers using a Policy Enforcement profile or a Web Acceleration profile. Systems that do not have BIG-IP AAM module provisioned are not vulnerable. The Traffic Management Microkernel (TMM) may restart and temporarily fail to process traffic. Systems that do not have BIG-IP AAM or PEM module provisioned are not vulnerable.
Published: 2017-10-27
Score: 5.9 Medium
EPSS: 4.6% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2017-15225 In F5 BIG-IP AAM and PEM software version 12.0.0 to 12.1.1, 11.6.0 to 11.6.1, 11.4.1 to 11.5.4, a remote attacker may create maliciously crafted HTTP request to cause Traffic Management Microkernel (TMM) to restart and temporarily fail to process traffic. This issue is exposed on virtual servers using a Policy Enforcement profile or a Web Acceleration profile. Systems that do not have BIG-IP AAM module provisioned are not vulnerable. The Traffic Management Microkernel (TMM) may restart and temporarily fail to process traffic. Systems that do not have BIG-IP AAM or PEM module provisioned are not vulnerable.
History

No history.

Subscriptions

F5 Big-ip Application Acceleration Manager Big-ip Policy Enforcement Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: f5

Published:

Updated: 2024-09-16T20:52:51.782Z

Reserved: 2017-02-21T00:00:00.000Z

Link: CVE-2017-6160

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2017-10-27T14:29:00.357

Modified: 2026-05-13T00:24:29.033

Link: CVE-2017-6160

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses