F5 Networks BIG-IP : TMM with LRO vulnerability (K07550539)

medium Nessus Plugin ID 118624


The remote device is missing a vendor-supplied security patch.


When Large Receive Offload (LRO) is enabled, undisclosed traffic patterns may cause TMM to restart. LRO has been available since 11.4.0 but is not enabled by default until13.1.0 for all platformsand 12.0.0 for Virtual Edition. (CVE-2018-15311)


An attacker may be able to disrupt traffic or cause the BIG-IP system to fail over to another device in the device group.

Note : This vulnerability is not exposed unless Large Receive Offload (LRO) is enabled. For more information about LRO being enabled by default, refer toK33612400: TCP Large Receive Offload tm.tcplargereceiveoffload database variable is enabled by default.


Upgrade to one of the non-vulnerable versions listed in the F5 Solution K07550539.

See Also


Plugin Details

Severity: Medium

ID: 118624

File Name: f5_bigip_SOL07550539.nasl

Version: 1.5

Type: local

Published: 11/2/2018

Updated: 11/2/2023

Supported Sensors: Nessus

Risk Information


Risk Factor: Low

Score: 3.6


Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.2

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:N/A:P

CVSS Score Source: CVE-2018-15311


Risk Factor: Medium

Base Score: 5.9

Temporal Score: 5.2

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:f5:big-ip_access_policy_manager, cpe:/a:f5:big-ip_advanced_firewall_manager, cpe:/a:f5:big-ip_application_acceleration_manager, cpe:/a:f5:big-ip_application_security_manager, cpe:/a:f5:big-ip_application_visibility_and_reporting, cpe:/a:f5:big-ip_domain_name_system, cpe:/a:f5:big-ip_global_traffic_manager, cpe:/a:f5:big-ip_link_controller, cpe:/a:f5:big-ip_local_traffic_manager, cpe:/a:f5:big-ip_policy_enforcement_manager, cpe:/a:f5:big-ip_webaccelerator, cpe:/h:f5:big-ip

Required KB Items: Host/local_checks_enabled, Host/BIG-IP/hotfix, Host/BIG-IP/modules, Host/BIG-IP/version

Exploit Ease: No known exploits are available

Patch Publication Date: 10/9/2018

Vulnerability Publication Date: 10/10/2018

Reference Information

CVE: CVE-2018-15311