PT-2014-8694 · F5+2 · F5 Asm+15
Brian Smith
+2
·
Published
2014-12-10
·
Updated
2017-01-03
·
CVE-2014-8730
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
F5 BIG-IP LTM, APM, and ASM versions 10.0.0 through 10.2.4 and 11.0.0 through 11.5.1
F5 AAM versions 11.4.0 through 11.5.1
F5 AFM versions 11.3.0 through 11.5.1
F5 Analytics versions 11.0.0 through 11.5.1
F5 Edge Gateway, WebAccelerator, and WOM versions 10.1.0 through 10.2.4 and 11.0.0 through 11.3.0
F5 PEM versions 11.3.0 through 11.6.0
F5 PSM versions 10.0.0 through 10.2.4 and 11.0.0 through 11.4.1
F5 BIG-IQ Cloud and Security versions 4.0.0 through 4.4.0
F5 BIG-IQ Device versions 4.2.0 through 4.4.0
PAN-OS versions 6.1.1 and earlier, 6.0.8 and earlier, 5.0.15 and earlier
Description
The vulnerability is due to improper block cipher padding implemented in TLSv1 when using Cipher Block Chaining (CBC) mode. An attacker could exploit the vulnerability to perform an "oracle padding" side channel attack on the cryptographic message. A successful exploit could allow the attacker to access sensitive information, such as HTTP cookies or other HTTP authorization content. This issue is a variant of the POODLE vulnerability and can be exploited through a man-in-the-middle attack, requiring the attacker to have access to a trusted, internal network.
Recommendations
For F5 BIG-IP LTM, APM, and ASM versions 10.0.0 through 10.2.4 and 11.0.0 through 11.5.1, update to a version outside of the affected range.
For F5 AAM versions 11.4.0 through 11.5.1, update to a version outside of the affected range.
For F5 AFM versions 11.3.0 through 11.5.1, update to a version outside of the affected range.
For F5 Analytics versions 11.0.0 through 11.5.1, update to a version outside of the affected range.
For F5 Edge Gateway, WebAccelerator, and WOM versions 10.1.0 through 10.2.4 and 11.0.0 through 11.3.0, update to a version outside of the affected range.
For F5 PEM versions 11.3.0 through 11.6.0, update to a version outside of the affected range.
For F5 PSM versions 10.0.0 through 10.2.4 and 11.0.0 through 11.4.1, update to a version outside of the affected range.
For F5 BIG-IQ Cloud and Security versions 4.0.0 through 4.4.0, update to a version outside of the affected range.
For F5 BIG-IQ Device versions 4.2.0 through 4.4.0, update to a version outside of the affected range.
For PAN-OS versions 6.1.1 and earlier, 6.0.8 and earlier, 5.0.15 and earlier, update to a version outside of the affected range.
As a temporary workaround, consider disabling the use of TLS 1.x with CBC cipher modes until a patch is available. Restrict access to sensitive information and limit the likelihood of a successful exploit by implementing additional security measures, such as monitoring for suspicious activity and limiting access to trusted networks.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Asa
Cisco Ios
F5 Aam
F5 Afm
F5 Apm
F5 Asm
F5 Analytics
F5 Big-Ip Ltm
F5 Big-Iq Cloud/Security
F5 Big-Iq Device
F5 Edge Gateway
F5 Pem
F5 Psm
F5 Wom
F5 Webaccelerator
Pan-Os