Vulnerability Name: CVE-2017-0303 (CCN-134155) Assigned: 2016-11-09 Published: 2017-10-26 Updated: 2019-10-03 Summary: In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and Websafe software version 13.0.0, 12.0.0 to 12.1.2 and 11.5.1 to 11.6.1, under limited circumstances connections handled by a Virtual Server with an associated SOCKS profile may not be properly cleaned up, potentially leading to resource starvation. Connections may be left in the connection table which then can only be removed by restarting TMM. Over time this may lead to the BIG-IP being unable to process further connections. CVSS v3 Severity: 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H )6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): High
7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H )6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): High
CVSS v2 Severity: 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAuthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Partial
7.8 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Complete
Vulnerability Type: CWE-459 Vulnerability Consequences: Denial of Service References: Source: MITRE Type: CNACVE-2017-0303 Source: BID Type: Third Party Advisory, VDB Entry101612 Source: CCN Type: BID-101612Multiple F5 BIG-IP Products CVE-2017-0303 Denial of Service Vulnerability Source: SECTRACK Type: Third Party Advisory, VDB Entry1039674 Source: XF Type: UNKNOWNf5-bigip-cve20170303-dos(134155) Source: CCN Type: F5 Security Advisory K30201296SOCKS proxy vulnerability CVE-2017-0303 Source: CONFIRM Type: Vendor Advisoryhttps://support.f5.com/csp/article/K30201296 Vulnerable Configuration: Configuration 1 :cpe:/a:f5:big-ip_local_traffic_manager:11.5.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:11.5.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:11.5.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:11.5.3:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:11.5.4:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:11.5.5:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:11.6.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:11.6.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:12.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:12.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:12.1.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:12.1.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:13.0.0:*:*:*:*:*:*:* Configuration 2 :cpe:/a:f5:big-ip_application_acceleration_manager:11.5.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_acceleration_manager:11.5.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_acceleration_manager:11.5.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_acceleration_manager:11.5.3:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_acceleration_manager:11.5.4:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_acceleration_manager:11.5.5:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_acceleration_manager:11.6.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_acceleration_manager:11.6.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_acceleration_manager:12.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_acceleration_manager:12.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_acceleration_manager:12.1.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_acceleration_manager:12.1.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_acceleration_manager:13.0.0:*:*:*:*:*:*:* Configuration 3 :cpe:/a:f5:big-ip_advanced_firewall_manager:11.5.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_advanced_firewall_manager:11.5.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_advanced_firewall_manager:11.5.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_advanced_firewall_manager:11.5.3:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_advanced_firewall_manager:11.5.4:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_advanced_firewall_manager:11.5.5:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_advanced_firewall_manager:11.6.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_advanced_firewall_manager:11.6.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_advanced_firewall_manager:12.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_advanced_firewall_manager:12.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_advanced_firewall_manager:12.1.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_advanced_firewall_manager:12.1.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_advanced_firewall_manager:13.0.0:*:*:*:*:*:*:* Configuration 4 :cpe:/a:f5:big-ip_access_policy_manager:11.5.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:11.5.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:11.5.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:11.5.3:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:11.5.4:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:11.5.5:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:11.6.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:11.6.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:12.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:12.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:12.1.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:12.1.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:13.0.0:*:*:*:*:*:*:* Configuration 5 :cpe:/a:f5:big-ip_application_security_manager:11.5.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:11.5.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:11.5.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:11.5.3:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:11.5.4:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:11.5.5:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:11.6.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:11.6.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:12.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:12.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:12.1.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:12.1.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:13.0.0:*:*:*:*:*:*:* Configuration 6 :cpe:/a:f5:big-ip_link_controller:11.5.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:11.5.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:11.5.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:11.5.3:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:11.5.4:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:11.5.5:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:11.6.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:11.6.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:12.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:12.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:12.1.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:12.1.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:13.0.0:*:*:*:*:*:*:* Configuration 7 :cpe:/a:f5:big-ip_policy_enforcement_manager:11.5.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_policy_enforcement_manager:11.5.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_policy_enforcement_manager:11.5.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_policy_enforcement_manager:11.5.3:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_policy_enforcement_manager:11.5.4:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_policy_enforcement_manager:11.5.5:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_policy_enforcement_manager:11.6.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_policy_enforcement_manager:11.6.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_policy_enforcement_manager:12.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_policy_enforcement_manager:12.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_policy_enforcement_manager:12.1.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_policy_enforcement_manager:12.1.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_policy_enforcement_manager:13.0.0:*:*:*:*:*:*:* Configuration 8 :cpe:/a:f5:big-ip_websafe:1.0.0:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:f5:big-ip_local_traffic_manager:13.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_acceleration_manager:13.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_afm:13.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_analytics:13.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:13.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_asm:13.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_dns:13.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:13.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_pem:13.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_websafe:13.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:12.1.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:12.1.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:12.1.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_websafe:12.1.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_analytics:12.1.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_dns:12.1.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:12.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_analytics:12.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:12.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_dns:12.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:12.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_pem:12.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_websafe:12.0.0:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
f5 big-ip local traffic manager 11.5.0
f5 big-ip local traffic manager 11.5.1
f5 big-ip local traffic manager 11.5.2
f5 big-ip local traffic manager 11.5.3
f5 big-ip local traffic manager 11.5.4
f5 big-ip local traffic manager 11.5.5
f5 big-ip local traffic manager 11.6.0
f5 big-ip local traffic manager 11.6.1
f5 big-ip local traffic manager 12.0.0
f5 big-ip local traffic manager 12.1.0
f5 big-ip local traffic manager 12.1.1
f5 big-ip local traffic manager 12.1.2
f5 big-ip local traffic manager 13.0.0
f5 big-ip application acceleration manager 11.5.0
f5 big-ip application acceleration manager 11.5.1
f5 big-ip application acceleration manager 11.5.2
f5 big-ip application acceleration manager 11.5.3
f5 big-ip application acceleration manager 11.5.4
f5 big-ip application acceleration manager 11.5.5
f5 big-ip application acceleration manager 11.6.0
f5 big-ip application acceleration manager 11.6.1
f5 big-ip application acceleration manager 12.0.0
f5 big-ip application acceleration manager 12.1.0
f5 big-ip application acceleration manager 12.1.1
f5 big-ip application acceleration manager 12.1.2
f5 big-ip application acceleration manager 13.0.0
f5 big-ip advanced firewall manager 11.5.0
f5 big-ip advanced firewall manager 11.5.1
f5 big-ip advanced firewall manager 11.5.2
f5 big-ip advanced firewall manager 11.5.3
f5 big-ip advanced firewall manager 11.5.4
f5 big-ip advanced firewall manager 11.5.5
f5 big-ip advanced firewall manager 11.6.0
f5 big-ip advanced firewall manager 11.6.1
f5 big-ip advanced firewall manager 12.0.0
f5 big-ip advanced firewall manager 12.1.0
f5 big-ip advanced firewall manager 12.1.1
f5 big-ip advanced firewall manager 12.1.2
f5 big-ip advanced firewall manager 13.0.0
f5 big-ip access policy manager 11.5.0
f5 big-ip access policy manager 11.5.1
f5 big-ip access policy manager 11.5.2
f5 big-ip access policy manager 11.5.3
f5 big-ip access policy manager 11.5.4
f5 big-ip access policy manager 11.5.5
f5 big-ip access policy manager 11.6.0
f5 big-ip access policy manager 11.6.1
f5 big-ip access policy manager 12.0.0
f5 big-ip access policy manager 12.1.0
f5 big-ip access policy manager 12.1.1
f5 big-ip access policy manager 12.1.2
f5 big-ip access policy manager 13.0.0
f5 big-ip application security manager 11.5.0
f5 big-ip application security manager 11.5.1
f5 big-ip application security manager 11.5.2
f5 big-ip application security manager 11.5.3
f5 big-ip application security manager 11.5.4
f5 big-ip application security manager 11.5.5
f5 big-ip application security manager 11.6.0
f5 big-ip application security manager 11.6.1
f5 big-ip application security manager 12.0.0
f5 big-ip application security manager 12.1.0
f5 big-ip application security manager 12.1.1
f5 big-ip application security manager 12.1.2
f5 big-ip application security manager 13.0.0
f5 big-ip link controller 11.5.0
f5 big-ip link controller 11.5.1
f5 big-ip link controller 11.5.2
f5 big-ip link controller 11.5.3
f5 big-ip link controller 11.5.4
f5 big-ip link controller 11.5.5
f5 big-ip link controller 11.6.0
f5 big-ip link controller 11.6.1
f5 big-ip link controller 12.0.0
f5 big-ip link controller 12.1.0
f5 big-ip link controller 12.1.1
f5 big-ip link controller 12.1.2
f5 big-ip link controller 13.0.0
f5 big-ip policy enforcement manager 11.5.0
f5 big-ip policy enforcement manager 11.5.1
f5 big-ip policy enforcement manager 11.5.2
f5 big-ip policy enforcement manager 11.5.3
f5 big-ip policy enforcement manager 11.5.4
f5 big-ip policy enforcement manager 11.5.5
f5 big-ip policy enforcement manager 11.6.0
f5 big-ip policy enforcement manager 11.6.1
f5 big-ip policy enforcement manager 12.0.0
f5 big-ip policy enforcement manager 12.1.0
f5 big-ip policy enforcement manager 12.1.1
f5 big-ip policy enforcement manager 12.1.2
f5 big-ip policy enforcement manager 13.0.0
f5 big-ip websafe 1.0.0
f5 big-ip local traffic manager 13.0.0
f5 big-ip aam 13.0.0
f5 big-ip afm 13.0.0
f5 big-ip analytics 13.0.0
f5 big-ip access policy manager 13.0.0
f5 big-ip asm 13.0.0
f5 big-ip dns 13.0.0
f5 big-ip link controller 13.0.0
f5 big-ip pem 13.0.0
f5 big-ip websafe 13.0.0
f5 big-ip local traffic manager 12.1.2
f5 big-ip access policy manager 12.1.2
f5 big-ip link controller 12.1.2
f5 big-ip websafe 12.1.2
f5 big-ip analytics 12.1.2
f5 big-ip dns 12.1.2
f5 big-ip local traffic manager 12.0.0
f5 big-ip analytics 12.0.0
f5 big-ip access policy manager 12.0.0
f5 big-ip dns 12.0.0
f5 big-ip link controller 12.0.0
f5 big-ip pem 12.0.0
f5 big-ip websafe 12.0.0