CVE-2017-6141 - CVE House
Back to Database
Status published Medium CVE-2017-6141

In F5 BIG-IP LTM, AAM, AFM, APM, ASM, Link Controller,...

Vulnerability Description

In F5 BIG-IP LTM, AAM, AFM, APM, ASM, Link Controller, PEM, and WebSafe 12.1.0 through 12.1.2, certain values in a TLS abbreviated handshake when using a client SSL profile with the Session Ticket option enabled may cause disruption of service to the Traffic Management Microkernel (TMM). The Session Ticket option is disabled by default.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-6141

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

F5 Networks, Inc.

View all reports →

Affected Software

F5 BIG-IP LTM, AAM, AFM, APM, ASM, Link Controller, PEM, WebSafe
Vulnerable Versions:
12.1.0 through 12.1.2

Timeline

Official Publish: October 20th, 2017
Last Modified: September 16th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.