Vulnerability Name: CVE-2013-6016 (CCN-88166) Assigned: 2013-10-16 Published: 2013-10-16 Updated: 2017-08-29 Summary: The Traffic Management Microkernel (TMM) in F5 BIG-IP LTM, APM, ASM, Edge Gateway, GTM, Link Controller, and WOM 10.0.0 through 10.2.2 and 11.0.0; Analytics 11.0.0; PSM 9.4.0 through 9.4.8, 10.0.0 through 10.2.4, and 11.0.0 through 11.4.1; and WebAccelerator 9.4.0 through 9.4.8, 10.0.0 through 10.2.4, and 11.0.0 through 11.3.0 might change a TCP connection to the ESTABLISHED state before receiving the ACK packet, which allows remote attackers to cause a denial of service (SIGFPE or assertion failure and TMM restart) via unspecified vectors. CVSS v3 Severity: 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Low
CVSS v2 Severity: 7.8 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C )5.8 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAuthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Complete
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P )3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Partial
Vulnerability Type: CWE-20 Vulnerability Consequences: Denial of Service References: Source: MITRE Type: CNACVE-2013-6016 Source: CCN Type: SA55378F5 Products Traffic Management Microkernel Denial of Service Vulnerability Source: SECUNIA Type: Vendor Advisory55378 Source: CCN Type: F5 KNOWLEDGE BASE SOL13233TMM vulnerability CVE-2013-6016 Source: CONFIRM Type: Vendor Advisoryhttp://support.f5.com/kb/en-us/solutions/public/13000/200/sol13233.html Source: SECTRACK Type: UNKNOWN1029220 Source: XF Type: UNKNOWNf5-cve20136016-dos(88166) Source: XF Type: UNKNOWNf5-cve20136016-dos(88166) Vulnerable Configuration: Configuration 1 :cpe:/a:f5:big-ip_global_traffic_manager:10.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_global_traffic_manager:10.0.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_global_traffic_manager:10.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_global_traffic_manager:10.2.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_global_traffic_manager:10.2.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_global_traffic_manager:10.2.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_global_traffic_manager:11.0.0:*:*:*:*:*:*:* Configuration 2 :cpe:/a:f5:big-ip_webaccelerator:9.4.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:9.4.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:9.4.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:9.4.3:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:9.4.4:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:9.4.5:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:9.4.6:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:9.4.7:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:9.4.8:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:10.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:10.0.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:10.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:10.2.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:10.2.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:10.2.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:10.2.3:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:10.2.4:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:11.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:11.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:11.2.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:11.2.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:11.3.0:*:*:*:*:*:*:* Configuration 3 :cpe:/a:f5:big-ip_local_traffic_manager:10.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:10.0.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:10.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:10.2.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:10.2.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:10.2.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:11.0.0:*:*:*:*:*:*:* Configuration 4 :cpe:/a:f5:big-ip_application_security_manager:10.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:10.0.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:10.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:10.2.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:10.2.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:10.2.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:11.0.0:*:*:*:*:*:*:* Configuration 5 :cpe:/a:f5:big-ip_access_policy_manager:10.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:10.2.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:10.2.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:10.2.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:11.0.0:*:*:*:*:*:*:* Configuration 6 :cpe:/a:f5:big-ip_wan_optimization_manager:10.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_wan_optimization_manager:10.0.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_wan_optimization_manager:10.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_wan_optimization_manager:10.2.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_wan_optimization_manager:10.2.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_wan_optimization_manager:10.2.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_wan_optimization_manager:11.0.0:*:*:*:*:*:*:* Configuration 7 :cpe:/a:f5:big-ip_edge_gateway:10.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_edge_gateway:10.2.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_edge_gateway:10.2.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_edge_gateway:10.2.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_edge_gateway:11.0.0:*:*:*:*:*:*:* Configuration 8 :cpe:/a:f5:big-ip_protocol_security_module:9.4.5:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_protocol_security_module:9.4.6:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_protocol_security_module:9.4.7:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_protocol_security_module:9.4.8:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_protocol_security_module:10.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_protocol_security_module:10.0.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_protocol_security_module:10.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_protocol_security_module:10.2.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_protocol_security_module:10.2.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_protocol_security_module:10.2.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_protocol_security_module:10.2.3:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_protocol_security_module:10.2.4:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_protocol_security_module:11.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_protocol_security_module:11.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_protocol_security_module:11.2.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_protocol_security_module:11.2.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_protocol_security_module:11.3.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_protocol_security_module:11.4.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_protocol_security_module:11.4.1:*:*:*:*:*:*:* Configuration 9 :cpe:/a:f5:big-ip_link_controller:10.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:10.0.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:10.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:10.2.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:10.2.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:10.2.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:11.0.0:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:f5:big-ip_application_security_manager:10.0.0:*:*:*:*:*:*:* OR cpe:/o:f5:tmos:10.0.0:*:*:*:*:*:*:* OR cpe:/o:f5:tmos:9.0:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
f5 big-ip global traffic manager 10.0.0
f5 big-ip global traffic manager 10.0.1
f5 big-ip global traffic manager 10.1.0
f5 big-ip global traffic manager 10.2.0
f5 big-ip global traffic manager 10.2.1
f5 big-ip global traffic manager 10.2.2
f5 big-ip global traffic manager 11.0.0
f5 big-ip webaccelerator 9.4.0
f5 big-ip webaccelerator 9.4.1
f5 big-ip webaccelerator 9.4.2
f5 big-ip webaccelerator 9.4.3
f5 big-ip webaccelerator 9.4.4
f5 big-ip webaccelerator 9.4.5
f5 big-ip webaccelerator 9.4.6
f5 big-ip webaccelerator 9.4.7
f5 big-ip webaccelerator 9.4.8
f5 big-ip webaccelerator 10.0.0
f5 big-ip webaccelerator 10.0.1
f5 big-ip webaccelerator 10.1.0
f5 big-ip webaccelerator 10.2.0
f5 big-ip webaccelerator 10.2.1
f5 big-ip webaccelerator 10.2.2
f5 big-ip webaccelerator 10.2.3
f5 big-ip webaccelerator 10.2.4
f5 big-ip webaccelerator 11.0.0
f5 big-ip webaccelerator 11.1.0
f5 big-ip webaccelerator 11.2.0
f5 big-ip webaccelerator 11.2.1
f5 big-ip webaccelerator 11.3.0
f5 big-ip local traffic manager 10.0.0
f5 big-ip local traffic manager 10.0.1
f5 big-ip local traffic manager 10.1.0
f5 big-ip local traffic manager 10.2.0
f5 big-ip local traffic manager 10.2.1
f5 big-ip local traffic manager 10.2.2
f5 big-ip local traffic manager 11.0.0
f5 big-ip application security manager 10.0.0
f5 big-ip application security manager 10.0.1
f5 big-ip application security manager 10.1.0
f5 big-ip application security manager 10.2.0
f5 big-ip application security manager 10.2.1
f5 big-ip application security manager 10.2.2
f5 big-ip application security manager 11.0.0
f5 big-ip access policy manager 10.1.0
f5 big-ip access policy manager 10.2.0
f5 big-ip access policy manager 10.2.1
f5 big-ip access policy manager 10.2.2
f5 big-ip access policy manager 11.0.0
f5 big-ip wan optimization manager 10.0.0
f5 big-ip wan optimization manager 10.0.1
f5 big-ip wan optimization manager 10.1.0
f5 big-ip wan optimization manager 10.2.0
f5 big-ip wan optimization manager 10.2.1
f5 big-ip wan optimization manager 10.2.2
f5 big-ip wan optimization manager 11.0.0
f5 big-ip edge gateway 10.1.0
f5 big-ip edge gateway 10.2.0
f5 big-ip edge gateway 10.2.1
f5 big-ip edge gateway 10.2.2
f5 big-ip edge gateway 11.0.0
f5 big-ip protocol security module 9.4.5
f5 big-ip protocol security module 9.4.6
f5 big-ip protocol security module 9.4.7
f5 big-ip protocol security module 9.4.8
f5 big-ip protocol security module 10.0.0
f5 big-ip protocol security module 10.0.1
f5 big-ip protocol security module 10.1.0
f5 big-ip protocol security module 10.2.0
f5 big-ip protocol security module 10.2.1
f5 big-ip protocol security module 10.2.2
f5 big-ip protocol security module 10.2.3
f5 big-ip protocol security module 10.2.4
f5 big-ip protocol security module 11.0.0
f5 big-ip protocol security module 11.1.0
f5 big-ip protocol security module 11.2.0
f5 big-ip protocol security module 11.2.1
f5 big-ip protocol security module 11.3.0
f5 big-ip protocol security module 11.4.0
f5 big-ip protocol security module 11.4.1
f5 big-ip link controller 10.0.0
f5 big-ip link controller 10.0.1
f5 big-ip link controller 10.1.0
f5 big-ip link controller 10.2.0
f5 big-ip link controller 10.2.1
f5 big-ip link controller 10.2.2
f5 big-ip link controller 11.0.0
f5 big-ip application security manager 10.0.0
f5 tmos 10.0.0
f5 tmos 9.0