CVE-2017-6162: F5 BIG-IP Access Policy Manager
Medium severity, CVSS 5.9. EPSS: 1.7% chance of exploitation in the next 30 days.
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, Websafe software version 12.0.0 to 12.1.2, 11.6.0 to 11.6.1, 11.4.0 to 11.5.4, 11.2.1, in some cases TMM may crash when processing TCP traffic. This vulnerability affects TMM via a virtual server configured with TCP profile. Traffic processing is disrupted while Traffic Management Microkernel (TMM) restarts. If the affected BIG-IP system is configured to be part of a device group, it will trigger a failover to the peer device.
Affected products
- F5 BIG-IP Access Policy Manager: from 11.5.0, up to and including 11.5.4; version 11.2.1 only; version 11.6.0 only; version 11.6.1 only; version 12.0.0 only; version 12.1.0 only; …
- F5 BIG-IP Advanced Firewall Manager: from 11.5.0, up to and including 11.5.4; version 11.2.1 only; version 11.6.0 only; version 11.6.1 only; version 12.0.0 only; version 12.1.0 only; …
- F5 BIG-IP Application Acceleration Manager: from 11.5.0, up to and including 11.5.4; version 11.2.1 only; version 11.6.0 only; version 11.6.1 only; version 12.0.0 only; version 12.1.0 only; …
- F5 BIG-IP Application Security Manager: from 11.5.0, up to and including 11.5.4; version 11.2.1 only; version 11.6.0 only; version 11.6.1 only; version 12.0.0 only; version 12.1.0 only; …
- F5 BIG-IP Link Controller: from 11.5.0, up to and including 11.5.4; version 11.2.1 only; version 11.6.0 only; version 11.6.1 only; version 12.0.0 only; version 12.1.0 only; …
- F5 BIG-IP Local Traffic Manager: from 11.5.0, up to and including 11.5.4; version 11.2.1 only; version 11.6.0 only; version 11.6.1 only; version 12.0.0 only; version 12.1.0 only; …
- F5 BIG-IP Policy Enforcement Manager: from 11.5.0, up to and including 11.5.4; version 11.2.1 only; version 11.6.0 only; version 11.6.1 only; version 12.0.0 only; version 12.1.0 only; …
- F5 BIG-IP Websafe: version 1.0.0 only
Published 2017-10-27. Last modified 2026-06-17.