QID 379403
Date Published: 2024-02-28
QID 379403: F5 BIG-IP AFM AFM Signature Matching Vulnerability (K000137595)
CVE-2024-21771: For unspecified traffic patterns, BIG-IP AFM IPS engine may spend an excessive amount of time matching the traffic against signatures, resulting in Traffic Management Microkernel (TMM) restarting and traffic disruption.
Affected Versions:
F5 BIG-IP (AFM) version 17.1.0
F5 BIG-IP (AFM) version 16.1.0 - 16.1.3
F5 BIG-IP (AFM) version 15.1.0 - 15.1.8
QID Detection Logic (Authenticated):
This QID checks for vulnerable version of F5 BIG-IP by running the 'tmsh -q show /sys version' command.
When attackers exploit this vulnerability, the TMM restarts and the BIG-IP system temporarily fails to process traffic while it recovers.
Solution
Please check the fixed versions released by the vendor in K000137595
Vendor References
- K000137595 -
my.f5.com/manage/s/article/K000137595
CVEs related to QID 379403
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K000137595 |
|