QID 379402
Date Published: 2024-02-29
QID 379402: F5 BIG-IP AFM Denial of Service (DoS) Vulnerability (K000137521)
CVE-2024-21763: When BIG-IP AFM Device DoS or DoS profile is configured with NXDOMAIN attack vector and bad actor detection, undisclosed queries can cause the Traffic Management Microkernel (TMM) to terminate.
Affected Versions:
F5 BIG-IP (AFM) version 17.1.0
F5 BIG-IP (AFM) version 16.1.0 - 16.1.3
F5 BIG-IP (AFM) version 15.1.0 - 15.1.9
QID Detection Logic (Authenticated):
This QID checks for vulnerable version of F5 BIG-IP by running the 'tmsh -q show /sys version' command.
Successful exploitation of this vulnerability allows a remote unauthenticated attacker to cause a denial-of-service (DoS) on the BIG-IP system.
Solution
Please check the fixed versions released by the vendor in K000137521
Vendor References
- K000137521 -
my.f5.com/manage/s/article/K000137521
CVEs related to QID 379402
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K000137521 |
|