Vulnerability Intelligence Report
CVE-2017-6128
An attacker may be able to cause a denial-of-service (DoS) attack against the sshd component in F5 BIG-IP, Enterprise Manager, BIG-IQ, and iWorkflow.
No Active Exploit Signals
CVSS Base Score
7.5
HIGH
EPSS Probability:1.40%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| F5 Networks, Inc. | BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, Edge Gateway, GTM, Link Controller, PEM, PSM, WebAccelerator, WebSafe | varies depending on product - see https://support.f5.com/csp/article/K92140924 for table (affected) |
| F5 Networks, Inc. | Enterprise Manager | varies depending on product - see https://support.f5.com/csp/article/K92140924 for table (affected) |
| F5 Networks, Inc. | BIG-IQ Cloud, Device, Security, ADC, Centralized Management, Cloud and Orchestration | varies depending on product - see https://support.f5.com/csp/article/K92140924 for table (affected) |
| F5 Networks, Inc. | iWorkflow | varies depending on product - see https://support.f5.com/csp/article/K92140924 for table (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
1.403%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | F5, Inc. · Vendor · USA |
| Reserved | 2017-02-21T00:00:00 |
| Published | 2017-05-01T15:00:00 |
| Patch Date | 2017-04-21 |
| Last Updated | 2024-08-05T15:18:49 |
Community Chatter & Buzz