CVE-2017-6150: F5 BIG-IP Access Policy Manager
High severity, CVSS 7.5. EPSS: 1.7% chance of exploitation in the next 30 days.
Under certain conditions for F5 BIG-IP systems 13.0.0 or 12.1.0 - 12.1.3.1, using FastL4 profiles, when the Reassemble IP Fragments option is disabled (default), some specific large fragmented packets may restart the Traffic Management Microkernel (TMM).
Affected products
- F5 BIG-IP Access Policy Manager: from 12.1.0, up to and including 12.1.3.1; version 13.0.0 only
- F5 BIG-IP Advanced Firewall Manager: from 12.1.0, up to and including 12.1.3.1; version 13.0.0 only
- F5 BIG-IP Analytics: from 12.1.0, up to and including 12.1.3.1; version 13.0.0 only
- F5 BIG-IP Application Acceleration Manager: from 12.1.0, up to and including 12.1.3.1; version 13.0.0 only
- F5 BIG-IP Application Security Manager: from 12.1.0, up to and including 12.1.3.1; version 13.0.0 only
- F5 BIG-IP DNS: from 12.1.0, up to and including 12.1.3.1; version 13.0.0 only
- F5 BIG-IP Link Controller: from 12.1.0, up to and including 12.1.3.1; version 13.0.0 only
- F5 BIG-IP Local Traffic Manager: from 12.1.0, up to and including 12.1.3.1; version 13.0.0 only
- F5 BIG-IP Policy Enforcement Manager: from 12.1.0, up to and including 12.1.3.1; version 13.0.0 only
- F5 BIG-IP Websafe: from 12.1.0, up to and including 12.1.3.1; version 13.0.0 only
Published 2018-03-01. Last modified 2026-06-17.