CVE-2017-0303 describes a resource exhaustion vulnerability in various F5 BIG-IP products, including LTM, AAM, AFM, and others, across several software versions. Under specific circumstances, connections handled by a Virtual Server with an associated SOCKS profile may not be properly terminated, leading to a build-up of connections in the connection table. This can eventually cause the BIG-IP device to become unresponsive and unable to process new connections, requiring a restart of TMM to resolve. The vulnerability has a CVSSv3 score of 7.5 (HIGH), indicating a high impact on availability (A:H) with low attack complexity (AC:L) and no user interaction required (UI:N). It can be exploited remotely over the network (AV:N). Despite its severity, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting it has not garnered significant public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.5.0CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_local_traffic_manager:11.5.0:*:*:*:*:*:*:* | ||
11.5.1CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_local_traffic_manager:11.5.1:*:*:*:*:*:*:* | ||
11.5.2CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_local_traffic_manager:11.5.2:*:*:*:*:*:*:* | ||
11.5.3CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_local_traffic_manager:11.5.3:*:*:*:*:*:*:* | ||
11.5.4CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_local_traffic_manager:11.5.4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.