CVE-2017-6166
Estado: ModificadaMedia (5.9)—
In BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe software 12.0.0 to 12.1.1, in some cases the Traffic Management Microkernel (TMM) may crash when processing fragmented packets. This vulnerability affects TMM through a virtual server configured with a FastL4 profile. Traffic processing is disrupted while TMM restarts. If the affected BIG-IP system is configured as part of a device group, it will trigger a failover to the peer device.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 5.9
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.93%
- Percentil entre todas las CVEs puntuadas: 79
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (11)
CWE
- CWE-415
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2017-6166",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.9,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 2.2
}
]
},
"affected": [
{
"source": "f5sirt@f5.com",
"affectedData": [
{
"vendor": "F5 Networks, Inc.",
"product": "BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe",
"versions": [
{
"status": "affected",
"version": "12.0.0, 12.1.1"
}
]
}
]
}
],
"published": "2017-11-22T16:29:00.337",
"references": [
{
"url": "http://www.securityfocus.com/bid/102264",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "f5sirt@f5.com"
},
{
"url": "http://www.securitytracker.com/id/1039949",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "f5sirt@f5.com"
},
{
"url": "https://support.f5.com/csp/article/K65615624",
"tags": [
"Issue Tracking",
"Mitigation",
"Vendor Advisory"
],
"source": "f5sirt@f5.com"
},
{
"url": "http://www.securityfocus.com/bid/102264",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id/1039949",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://support.f5.com/csp/article/K65615624",
"tags": [
"Issue Tracking",
"Mitigation",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-415"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe software 12.0.0 to 12.1.1, in some cases the Traffic Management Microkernel (TMM) may crash when processing fragmented packets. This vulnerability affects TMM through a virtual server configured with a FastL4 profile. Traffic processing is disrupted while TMM restarts. If the affected BIG-IP system is configured as part of a device group, it will trigger a failover to the peer device."
},
{
"lang": "es",
"value": "En el software BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM y WebSafe desde la versión 12.0.0 a la 12.1.1, en algunos casos, el componente Traffic Management Microkernel (TMM) podría cerrarse inesperadamente al procesar paquetes fragmentados. Esta vulnerabilidad afecta al TMM mediante un servidor virtual configurado con perfil FastL4. El procesamiento del tráfico se interrumpe mientras el TMM (Traffic Management Microkernel) se reinicia. Si el sistema BIG-IP afectado está configurado como parte de un grupo de dispositivos, desencadenará una conmutación por error en el dispositivo del mismo nivel."
}
],
"lastModified": "2026-06-17T01:21:52.890",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:f5:big-ip_afm:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "55477759-BD0D-45A9-812B-E3E227DCD31A",
"versionEndIncluding": "12.1.1",
"versionStartIncluding": "12.0.0"
},
{
"criteria": "cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9A9F024E-74B6-4D90-AD0E-869BD0AF8BAD",
"versionEndIncluding": "12.1.1",
"versionStartIncluding": "12.0.0"
},
{
"criteria": "cpe:2.3:a:f5:big-ip_apm:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A84C593D-7A8C-49F4-A490-4D330D8BCBD8",
"versionEndIncluding": "12.1.1",
"versionStartIncluding": "12.0.0"
},
{
"criteria": "cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "10DAFC58-80B6-4BB6-9B74-8D4B122F5797",
"versionEndIncluding": "12.1.1",
"versionStartIncluding": "12.0.0"
},
{
"criteria": "cpe:2.3:a:f5:big-ip_asm:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FF47AC2C-F267-4B16-98E0-7D6676D55CE0",
"versionEndIncluding": "12.1.1",
"versionStartIncluding": "12.0.0"
},
{
"criteria": "cpe:2.3:a:f5:big-ip_dns:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EE031CCC-7CD0-44DE-B101-EB9181036775",
"versionEndIncluding": "12.1.1",
"versionStartIncluding": "12.0.0"
},
{
"criteria": "cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6B42DCF7-9DCD-4091-8553-8FF5D9417D6D",
"versionEndIncluding": "12.1.1",
"versionStartIncluding": "12.0.0"
},
{
"criteria": "cpe:2.3:a:f5:big-ip_ltm:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CB56B6D2-4BAB-4C20-B971-67CAF45FD08E",
"versionEndIncluding": "12.1.1",
"versionStartIncluding": "12.0.0"
},
{
"criteria": "cpe:2.3:a:f5:big-ip_pem:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B5A49CA8-47F8-4FF2-9ECD-5B1A2B444ED8",
"versionEndIncluding": "12.1.1",
"versionStartIncluding": "12.0.0"
},
{
"criteria": "cpe:2.3:a:f5:f5_websafe:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2BC666CC-14CC-4CCB-BD0E-88FDB18D298C",
"versionEndIncluding": "12.1.1",
"versionStartIncluding": "12.0.0"
},
{
"criteria": "cpe:2.3:a:f5:linerate:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E83ABC2C-AF58-423C-944D-8127881E2408",
"versionEndIncluding": "2.6.2",
"versionStartIncluding": "2.5.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "f5sirt@f5.com"
}