Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r475-j35v-6jmm

Опубликовано: 01 фев. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a BIG-IP AFM NAT policy with a destination NAT rule is configured on a FastL4 virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a BIG-IP AFM NAT policy with a destination NAT rule is configured on a FastL4 virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

EPSS

Процентиль: 66%
0.00509
Низкий

7.5 High

CVSS3

Дефекты

CWE-908

Связанные уязвимости

CVSS3: 7.5
nvd
около 3 лет назад

On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a BIG-IP AFM NAT policy with a destination NAT rule is configured on a FastL4 virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 7.5
fstec
около 3 лет назад

Уязвимость реализации технологии преобразования сетевых адресов Network Address Translation (NAT) виртуального сервера FastL4 межсетевых экранов BIG-IP Advanced Firewall Manager, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 66%
0.00509
Низкий

7.5 High

CVSS3

Дефекты

CWE-908