Vulnerabilities
Vulnerable Software
F5:  >> Big-Ip Analytics  >> 13.1.0  Security Vulnerabilities
On F5 BIG-IP versions 13.0.0 - 13.1.0.3, attackers may be able to disrupt services on the BIG-IP system with maliciously crafted client certificate. This vulnerability affects virtual servers associated with Client SSL profile which enables the use of client certificate authentication. Client certificate authentication is not enabled by default in Client SSL profile. There is no control plane exposure.
CVSS Score
7.5
EPSS Score
0.006
Published
2018-03-22
In some circumstances, the Traffic Management Microkernel (TMM) does not properly handle certain malformed Websockets requests/responses, which allows remote attackers to cause a denial-of-service (DoS) or possible remote code execution on the F5 BIG-IP system running versions 13.0.0 - 13.1.0.3 or 12.1.0 - 12.1.3.1.
CVSS Score
8.1
EPSS Score
0.033
Published
2018-03-22
On F5 BIG-IP versions 13.1.0 - 13.1.0.3, when ASM and AVR are both provisioned, TMM may restart while processing DNS requests when the virtual server is configured with a DNS profile and the Protocol setting is set to TCP.
CVSS Score
5.9
EPSS Score
0.015
Published
2018-03-22


Contact Us

Shodan ® - All rights reserved