CVE-2017-6144 - CVE House
Back to Database
Status published High CVE-2017-6144

In F5 BIG-IP PEM 12.1.0 through 12.1.2 when downloading the...

Vulnerability Description

In F5 BIG-IP PEM 12.1.0 through 12.1.2 when downloading the Type Allocation Code (TAC) database file via HTTPS, the server's certificate is not verified. Attackers in a privileged network position may be able to launch a man-in-the-middle attack against these connections. TAC databases are used in BIG-IP PEM for Device Type and OS (DTOS) and Tethering detection. Customers not using BIG-IP PEM, not configuring downloads of TAC database files, or not using HTTP for that download are not affected.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-6144

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

F5 Networks, Inc.

View all reports →

Affected Software

F5 BIG-IP PEM
Vulnerable Versions:
12.1.0 through 12.1.2

Timeline

Official Publish: October 20th, 2017
Last Modified: September 17th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.