CVE-2017-0303
Summary
| CVE | CVE-2017-0303 |
|---|---|
| State | PUBLISHED |
| Assigner | f5 |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-10-27 14:29:00 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and Websafe software version 13.0.0, 12.0.0 to 12.1.2 and 11.5.1 to 11.6.1, under limited circumstances connections handled by a Virtual Server with an associated SOCKS profile may not be properly cleaned up, potentially leading to resource starvation. Connections may be left in the connection table which then can only be removed by restarting TMM. Over time this may lead to the BIG-IP being unable to process further connections. |
Risk And Classification
Primary CVSS: v3.0 7.5 HIGH from [email protected]
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Problem Types: CWE-459 | denial of service
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 7.5 | HIGH | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| 2.0 | [email protected] | Primary | 5 | AV:N/AC:L/Au:N/C:N/I:N/A:P |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
HighCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:L/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | F5 | Big-ip Access Policy Manager | 11.5.0 | All | All | All |
| Application | F5 | Big-ip Access Policy Manager | 11.5.1 | All | All | All |
| Application | F5 | Big-ip Access Policy Manager | 11.5.2 | All | All | All |
| Application | F5 | Big-ip Access Policy Manager | 11.5.3 | All | All | All |
| Application | F5 | Big-ip Access Policy Manager | 11.5.4 | All | All | All |
| Application | F5 | Big-ip Access Policy Manager | 11.5.5 | All | All | All |
| Application | F5 | Big-ip Access Policy Manager | 11.6.0 | All | All | All |
| Application | F5 | Big-ip Access Policy Manager | 11.6.1 | All | All | All |
| Application | F5 | Big-ip Access Policy Manager | 12.0.0 | All | All | All |
| Application | F5 | Big-ip Access Policy Manager | 12.1.0 | All | All | All |
| Application | F5 | Big-ip Access Policy Manager | 12.1.1 | All | All | All |
| Application | F5 | Big-ip Access Policy Manager | 12.1.2 | All | All | All |
| Application | F5 | Big-ip Access Policy Manager | 13.0.0 | All | All | All |
| Application | F5 | Big-ip Advanced Firewall Manager | 11.5.0 | All | All | All |
| Application | F5 | Big-ip Advanced Firewall Manager | 11.5.1 | All | All | All |
| Application | F5 | Big-ip Advanced Firewall Manager | 11.5.2 | All | All | All |
| Application | F5 | Big-ip Advanced Firewall Manager | 11.5.3 | All | All | All |
| Application | F5 | Big-ip Advanced Firewall Manager | 11.5.4 | All | All | All |
| Application | F5 | Big-ip Advanced Firewall Manager | 11.5.5 | All | All | All |
| Application | F5 | Big-ip Advanced Firewall Manager | 11.6.0 | All | All | All |
| Application | F5 | Big-ip Advanced Firewall Manager | 11.6.1 | All | All | All |
| Application | F5 | Big-ip Advanced Firewall Manager | 12.0.0 | All | All | All |
| Application | F5 | Big-ip Advanced Firewall Manager | 12.1.0 | All | All | All |
| Application | F5 | Big-ip Advanced Firewall Manager | 12.1.1 | All | All | All |
| Application | F5 | Big-ip Advanced Firewall Manager | 12.1.2 | All | All | All |
| Application | F5 | Big-ip Advanced Firewall Manager | 13.0.0 | All | All | All |
| Application | F5 | Big-ip Application Acceleration Manager | 11.5.0 | All | All | All |
| Application | F5 | Big-ip Application Acceleration Manager | 11.5.1 | All | All | All |
| Application | F5 | Big-ip Application Acceleration Manager | 11.5.2 | All | All | All |
| Application | F5 | Big-ip Application Acceleration Manager | 11.5.3 | All | All | All |
| Application | F5 | Big-ip Application Acceleration Manager | 11.5.4 | All | All | All |
| Application | F5 | Big-ip Application Acceleration Manager | 11.5.5 | All | All | All |
| Application | F5 | Big-ip Application Acceleration Manager | 11.6.0 | All | All | All |
| Application | F5 | Big-ip Application Acceleration Manager | 11.6.1 | All | All | All |
| Application | F5 | Big-ip Application Acceleration Manager | 12.0.0 | All | All | All |
| Application | F5 | Big-ip Application Acceleration Manager | 12.1.0 | All | All | All |
| Application | F5 | Big-ip Application Acceleration Manager | 12.1.1 | All | All | All |
| Application | F5 | Big-ip Application Acceleration Manager | 12.1.2 | All | All | All |
| Application | F5 | Big-ip Application Acceleration Manager | 13.0.0 | All | All | All |
| Application | F5 | Big-ip Application Security Manager | 11.5.0 | All | All | All |
| Application | F5 | Big-ip Application Security Manager | 11.5.1 | All | All | All |
| Application | F5 | Big-ip Application Security Manager | 11.5.2 | All | All | All |
| Application | F5 | Big-ip Application Security Manager | 11.5.3 | All | All | All |
| Application | F5 | Big-ip Application Security Manager | 11.5.4 | All | All | All |
| Application | F5 | Big-ip Application Security Manager | 11.5.5 | All | All | All |
| Application | F5 | Big-ip Application Security Manager | 11.6.0 | All | All | All |
| Application | F5 | Big-ip Application Security Manager | 11.6.1 | All | All | All |
| Application | F5 | Big-ip Application Security Manager | 12.0.0 | All | All | All |
| Application | F5 | Big-ip Application Security Manager | 12.1.0 | All | All | All |
| Application | F5 | Big-ip Application Security Manager | 12.1.1 | All | All | All |
| Application | F5 | Big-ip Application Security Manager | 12.1.2 | All | All | All |
| Application | F5 | Big-ip Application Security Manager | 13.0.0 | All | All | All |
| Application | F5 | Big-ip Link Controller | 11.5.0 | All | All | All |
| Application | F5 | Big-ip Link Controller | 11.5.1 | All | All | All |
| Application | F5 | Big-ip Link Controller | 11.5.2 | All | All | All |
| Application | F5 | Big-ip Link Controller | 11.5.3 | All | All | All |
| Application | F5 | Big-ip Link Controller | 11.5.4 | All | All | All |
| Application | F5 | Big-ip Link Controller | 11.5.5 | All | All | All |
| Application | F5 | Big-ip Link Controller | 11.6.0 | All | All | All |
| Application | F5 | Big-ip Link Controller | 11.6.1 | All | All | All |
| Application | F5 | Big-ip Link Controller | 12.0.0 | All | All | All |
| Application | F5 | Big-ip Link Controller | 12.1.0 | All | All | All |
| Application | F5 | Big-ip Link Controller | 12.1.1 | All | All | All |
| Application | F5 | Big-ip Link Controller | 12.1.2 | All | All | All |
| Application | F5 | Big-ip Link Controller | 13.0.0 | All | All | All |
| Application | F5 | Big-ip Local Traffic Manager | 11.5.0 | All | All | All |
| Application | F5 | Big-ip Local Traffic Manager | 11.5.1 | All | All | All |
| Application | F5 | Big-ip Local Traffic Manager | 11.5.2 | All | All | All |
| Application | F5 | Big-ip Local Traffic Manager | 11.5.3 | All | All | All |
| Application | F5 | Big-ip Local Traffic Manager | 11.5.4 | All | All | All |
| Application | F5 | Big-ip Local Traffic Manager | 11.5.5 | All | All | All |
| Application | F5 | Big-ip Local Traffic Manager | 11.6.0 | All | All | All |
| Application | F5 | Big-ip Local Traffic Manager | 11.6.1 | All | All | All |
| Application | F5 | Big-ip Local Traffic Manager | 12.0.0 | All | All | All |
| Application | F5 | Big-ip Local Traffic Manager | 12.1.0 | All | All | All |
| Application | F5 | Big-ip Local Traffic Manager | 12.1.1 | All | All | All |
| Application | F5 | Big-ip Local Traffic Manager | 12.1.2 | All | All | All |
| Application | F5 | Big-ip Local Traffic Manager | 13.0.0 | All | All | All |
| Application | F5 | Big-ip Policy Enforcement Manager | 11.5.0 | All | All | All |
| Application | F5 | Big-ip Policy Enforcement Manager | 11.5.1 | All | All | All |
| Application | F5 | Big-ip Policy Enforcement Manager | 11.5.2 | All | All | All |
| Application | F5 | Big-ip Policy Enforcement Manager | 11.5.3 | All | All | All |
| Application | F5 | Big-ip Policy Enforcement Manager | 11.5.4 | All | All | All |
| Application | F5 | Big-ip Policy Enforcement Manager | 11.5.5 | All | All | All |
| Application | F5 | Big-ip Policy Enforcement Manager | 11.6.0 | All | All | All |
| Application | F5 | Big-ip Policy Enforcement Manager | 11.6.1 | All | All | All |
| Application | F5 | Big-ip Policy Enforcement Manager | 12.0.0 | All | All | All |
| Application | F5 | Big-ip Policy Enforcement Manager | 12.1.0 | All | All | All |
| Application | F5 | Big-ip Policy Enforcement Manager | 12.1.1 | All | All | All |
| Application | F5 | Big-ip Policy Enforcement Manager | 12.1.2 | All | All | All |
| Application | F5 | Big-ip Policy Enforcement Manager | 13.0.0 | All | All | All |
| Application | F5 | Big-ip Websafe | 1.0.0 | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | F5 Networks Inc. | BIG-IP LTM AAM AFM Analytics APM ASM DNS GTM Link Controller PEM Websafe | affected 13.0.0 | Not specified |
| CNA | F5 Networks Inc. | BIG-IP LTM AAM AFM Analytics APM ASM DNS GTM Link Controller PEM Websafe | affected 12.0.0 - 12.1.2 | Not specified |
| CNA | F5 Networks Inc. | BIG-IP LTM AAM AFM Analytics APM ASM DNS GTM Link Controller PEM Websafe | affected 11.5.1 - 11.6.1 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Multiple F5 BIG-IP Products CVE-2017-0303 Denial of Service Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| support.f5.com/csp/article/K30201296 | af854a3a-2127-422b-91ae-364da2661108 | support.f5.com | Vendor Advisory |
| F5 BIG-IP SOCKS Profile Processing Bug Lets Remote Users Deny Service - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.