QID 375794
Date Published: 2021-08-19
QID 375794: F5 BIG-IP ASM,LTM,APM Traffic Management Microkernel (TMM) Stream Control Transmission Protocol (SCTP) Vulnerability (K05300051)
F5 BIG-IP ASM (Application Security Manager) is a flexible web application firewall that secures web applications in traditional, virtual, and private cloud environments.
F5 BIG-IP (LTM) Local Traffic Manager is the most popular module offered on F5 Networks BIG-IP platform. The real power of the LTM is it is a Full Proxy, allowing you to augment client and server side connections. All while making informed load balancing decisions on availability, performance, and persistence.
F5 BIG-IP Access Policy Manager (APM) is a secure, flexible, high-performance solution that provides unified global access to your network, cloud, and applications.
The Traffic Management Microkernel (TMM) may stop responding when processing Stream Control Transmission Protocol (SCTP) traffic under certain conditions. This vulnerability affects TMM by way of a virtual server configured with an SCTP profile. (CVE-2021-23013)
Vulnerable Component: BIG-IP ASM, APM,LTM
Affected Versions:
16.0.0 - 16.0.1.0
15.1.0 - 15.1.2
14.1.0 - 14.1.3
13.1.0 - 13.1.3.5
12.1.0 - 12.1.5.2
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
Traffic processing is disrupted while TMM restarts. If the affected BIG-IP system is configured as part of a device group, the system triggers a failover to the peer device.
- K05300051 -
support.f5.com/csp/article/K05300051
CVEs related to QID 375794
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K05300051 |
|