F5 Networks BIG-IP : TMM with LRO vulnerability (K07550539)
Medium Nessus Plugin ID 118624
SynopsisThe remote device is missing a vendor-supplied security patch.
DescriptionWhen Large Receive Offload (LRO) is enabled, undisclosed traffic
patterns may cause TMM to restart. LRO has been available since 11.4.0
but is not enabled by default until13.1.0 for all platformsand 12.0.0
for Virtual Edition. (CVE-2018-15311)
An attacker may be able to disrupt traffic or cause the BIG-IP system
to fail over to another device in the device group.
Note : This vulnerability is not exposed unless Large Receive Offload
(LRO) is enabled. For more information about LRO being enabled by
default, refer toK33612400: TCP Large Receive Offload
tm.tcplargereceiveoffload database variable is enabled by default.
SolutionUpgrade to one of the non-vulnerable versions listed in the F5