5
CVSSv2

CVE-2015-8240

Published: 11/04/2016 Updated: 18/04/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The Traffic Management Microkernel (TMM) in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, GTM, Link Controller, and BIG-IP PEM prior to 11.4.1 HF10, 11.5.x prior to 11.5.4, and 11.6.x prior to 11.6.0 HF6 and BIG-IP PSM prior to 11.4.1 HF10 does not properly handle TCP options, which allows remote malicious users to cause a denial of service via unspecified vectors, related to the tm.minpathmtu database variable.

Vulnerable Product Search on Vulmon Subscribe to Product

f5 big-ip protocol security module 11.4.1

f5 big-ip policy enforcement manager 11.5.3

f5 big-ip global traffic manager 11.4.1

f5 big-ip global traffic manager 11.6.0

f5 big-ip analytics 11.4.1

f5 big-ip analytics 11.6.0

f5 big-ip local traffic manager 11.4.1

f5 big-ip policy enforcement manager 11.6.0

f5 big-ip link controller 11.4.1

f5 big-ip link controller 11.5.3

f5 big-ip link controller 11.6.0

f5 big-ip advanced firewall manager 11.5.3

f5 big-ip advanced firewall manager 11.6.0

f5 big-ip application acceleration manager 11.4.1

f5 big-ip application acceleration manager 11.5.3

f5 big-ip policy enforcement manager 11.4.1

f5 big-ip global traffic manager 11.5.3

f5 big-ip application security manager 11.4.1

f5 big-ip analytics 11.5.3

f5 big-ip advanced firewall manager 11.4.1

f5 big-ip application acceleration manager 11.6.0

f5 big-ip local traffic manager 11.5.3

f5 big-ip application security manager 11.5.3

f5 big-ip application security manager 11.6.0

f5 big-ip access policy manager 11.4.1

f5 big-ip access policy manager 11.5.3

f5 big-ip access policy manager 11.6.0

f5 big-ip local traffic manager 11.6.0