SB2017122003 - Denial of service in F5 Enterprise Manager
Published: December 22, 2017 Updated: December 25, 2017
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper input validation (CVE-ID: CVE-2017-6134)
The vulnerability allows an adjacent attacker to cause DoS condition on the target system.
The vulnerability exists in the default configuration due to insufficient validation of user-supplied input. An adjacent attacker can send specially crafted packets to cause the target Traffic Management Microkernel (TMM) to restart and traffic to disrupt.
Successful exploitation of the vulnerability results in denial of service.
Remediation
Install update from vendor's website.