Tracker / CVE-2019-6684
CVE-2019-6684
High 7.5
On versions 15.0.0-15.0.1.1, 14.0.0-14.1.2.2, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, under certain conditions, a multi-bladed BIG-IP Virtual Clustered Multiprocessing (vCMP) may drop broadcast packets when they are rebroadcast to the vCMP guest secondary blades. An attacker can leverage the fragmented broadcast IP packets to perform any type of fragmentation-based attack.
Affected products and versions
| f5 | big-ip_access_policy_manager · 11.5.2 → 11.6.5 |
|---|---|
| f5 | big-ip_access_policy_manager · 12.1.0 → 12.1.5 |
| f5 | big-ip_access_policy_manager · 13.0.0 → 13.1.3.2 |
| f5 | big-ip_access_policy_manager · 14.0.0 → 14.1.2.3 |
| f5 | big-ip_access_policy_manager · 15.0.0 → 15.1.0 |
| f5 | big-ip_advanced_firewall_manager · 11.5.2 → 11.6.5 |
| f5 | big-ip_advanced_firewall_manager · 12.1.0 → 12.1.5 |
| f5 | big-ip_advanced_firewall_manager · 13.0.0 → 13.1.3.2 |
| f5 | big-ip_advanced_firewall_manager · 14.0.0 → 14.1.2.3 |
| f5 | big-ip_advanced_firewall_manager · 15.0.0 → 15.1.0 |
| f5 | big-ip_analytics · 11.5.2 → 11.6.5 |
| f5 | big-ip_analytics · 12.1.0 → 12.1.5 |
| f5 | big-ip_analytics · 13.0.0 → 13.1.3.2 |
| f5 | big-ip_analytics · 14.0.0 → 14.1.2.3 |
| f5 | big-ip_analytics · 15.0.0 → 15.1.0 |
| f5 | big-ip_application_acceleration_manager · 11.5.2 → 11.6.5 |
| f5 | big-ip_application_acceleration_manager · 12.1.0 → 12.1.5 |
| f5 | big-ip_application_acceleration_manager · 13.0.0 → 13.1.3.2 |
| f5 | big-ip_application_acceleration_manager · 14.0.0 → 14.1.2.3 |
| f5 | big-ip_application_acceleration_manager · 15.0.0 → 15.1.0 |
| f5 | big-ip_application_security_manager · 11.5.2 → 11.6.5 |
| f5 | big-ip_application_security_manager · 12.1.0 → 12.1.5 |
| f5 | big-ip_application_security_manager · 13.0.0 → 13.1.3.2 |
| f5 | big-ip_application_security_manager · 14.0.0 → 14.1.2.3 |
| f5 | big-ip_application_security_manager · 15.0.0 → 15.1.0 |
| f5 | big-ip_domain_name_system · 11.5.2 → 11.6.5 |
| f5 | big-ip_domain_name_system · 12.1.0 → 12.1.5 |
| f5 | big-ip_domain_name_system · 13.0.0 → 13.1.3.2 |
| f5 | big-ip_domain_name_system · 14.0.0 → 14.1.2.3 |
| f5 | big-ip_domain_name_system · 15.0.0 → 15.1.0 |
| f5 | big-ip_fraud_protection_service · 11.5.2 → 11.6.5 |
| f5 | big-ip_fraud_protection_service · 12.1.0 → 12.1.5 |
| f5 | big-ip_fraud_protection_service · 13.0.0 → 13.1.3.2 |
| f5 | big-ip_fraud_protection_service · 14.0.0 → 14.1.2.3 |
| f5 | big-ip_fraud_protection_service · 15.0.0 → 15.1.0 |
| f5 | big-ip_global_traffic_manager · 11.5.2 → 11.6.5 |
| f5 | big-ip_global_traffic_manager · 12.1.0 → 12.1.5 |
| f5 | big-ip_global_traffic_manager · 13.0.0 → 13.1.3.2 |
| f5 | big-ip_global_traffic_manager · 14.0.0 → 14.1.2.3 |
| f5 | big-ip_global_traffic_manager · 15.0.0 → 15.1.0 |
| f5 | big-ip_link_controller · 11.5.2 → 11.6.5 |
| f5 | big-ip_link_controller · 12.1.0 → 12.1.5 |
| f5 | big-ip_link_controller · 13.0.0 → 13.1.3.2 |
| f5 | big-ip_link_controller · 14.0.0 → 14.1.2.3 |
| f5 | big-ip_link_controller · 15.0.0 → 15.1.0 |
| f5 | big-ip_local_traffic_manager · 11.5.2 → 11.6.5 |
| f5 | big-ip_local_traffic_manager · 12.1.0 → 12.1.5 |
| f5 | big-ip_local_traffic_manager · 13.0.0 → 13.1.3.2 |
| f5 | big-ip_local_traffic_manager · 14.0.0 → 14.1.2.3 |
| f5 | big-ip_local_traffic_manager · 15.0.0 → 15.1.0 |
| f5 | big-ip_policy_enforcement_manager · 11.5.2 → 11.6.5 |
| f5 | big-ip_policy_enforcement_manager · 12.1.0 → 12.1.5 |
| f5 | big-ip_policy_enforcement_manager · 13.0.0 → 13.1.3.2 |
| f5 | big-ip_policy_enforcement_manager · 14.0.0 → 14.1.2.3 |
| f5 | big-ip_policy_enforcement_manager · 15.0.0 → 15.1.0 |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.