#VU9747 Improper input validation in F5 Networks products - CVE-2017-6164
Published: December 25, 2017
BIG-IP LTM
BIG-IP AFM
BIG-IP Analytics
BIG-IP APM
BIG-IP ASM
BIG-IP GTM
BIG-IP PEM
BIG-IP AAM
BIG-IP DNS
BIG-IP Link Controller
BIG-IP Edge Gateway
BIG-IP WebAccelerator
BIG-IP WebSafe
F5 Networks
Description
The vulnerability allows a remote attacker to cause DoS condition or execute arbitrary commands on the target system.
The vulnerability exists in the default configuration due to insufficient validation of user-supplied input. A remote attacker can send specially crafted TLS 1.2 data, trigger a flaw in the ClientSSL profile component of the Traffic Management Microkernel (TMM) and cause it to crash or potentially execute commands on the target system.