QID 378986

Date Published: 2023-11-21

QID 378986: F5 BIG-IP Denial of Service (DoS) Vulnerability (K000133467)

Undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate when a client-side HTTP/2 profile and the HTTP MRF Router option are enabled

Affected Versions:
F5 BIG-IP version 17.1.0
F5 BIG-IP version 16.1.0 - 16.1.4
QID Detection Logic (Authenticated):
This QID checks for vulnerable version of F5 BIG-IP by running the 'tmsh -q show /sys version' command.

Successful exploit may lead to denial of service

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Vendor has released patch addressing the vulnerability. For more information, please refer to K000133467

    Vendor References

    CVEs related to QID 378986

    Software Advisories
    Advisory ID Software Component Link
    K000133467 URL Logo my.f5.com/manage/s/article/K000133467