PT-2019-18175 · F5 · Big-Ip
Published
1999-01-01
·
Updated
2021-07-21
·
CVE-2019-6593
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
BIG-IP versions 11.5.1 through 11.5.4
BIG-IP version 11.6.1
BIG-IP version 12.1.0
Description
A chosen ciphertext attack against CBC ciphers may be possible when a virtual server is configured with a Client SSL profile. This could result in plaintext recovery of encrypted messages through a man-in-the-middle (MITM) attack, without the attacker needing access to the server's private key.
Recommendations
For BIG-IP versions 11.5.1 through 11.5.4, update to a version that is not vulnerable to this issue.
For BIG-IP version 11.6.1, update to a version that is not vulnerable to this issue.
For BIG-IP version 12.1.0, update to a version that is not vulnerable to this issue.
As a temporary workaround, consider restricting the use of CBC ciphers in Client SSL profiles until a patch is available.
Fix
Use of a Broken Cryptographic Algorithm
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Big-Ip