QID 375528
Date Published: 2021-05-13
QID 375528: F5 BIG-IP TMM Vulnerability(K10751325)
F5's BIG-IP is a family of products covering software and hardware designed around application availability, access control, and security solutions.
CVE-2021-23011: Vulnerable component is Traffic Management Microkernel (TMM). When the BIG-IP system is buffering packet fragments for reassembly, the Traffic Management Microkernel (TMM) may consume an excessive amount of resources, eventually leading to a restart and failover event.
Vulnerable Component: BIG-IP all modules
Affected Versions:
16.0.0 - 16.0.1
15.0.0 - 15.1.2
14.1.0 - 14.1.3
13.1.0 - 13.1.3
12.1.0 - 12.1.5
11.6.1 - 11.6.5
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
The Traffic Management Microkernel (TMM) generates a core file and restarts. When configured as part of a high availability (HA) device group, the BIG-IP system fails over to the peer device.
- K10751325 -
support.f5.com/csp/article/K10751325
CVEs related to QID 375528
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K10751325 |
|