PT-2019-18211 · F5 · F5 Big-Ip
Published
2019-07-03
·
Updated
2023-02-16
·
CVE-2019-6629
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
F5 BIG-IP versions 14.1.0 through 14.1.0.5
Description
The issue occurs when undisclosed SSL traffic is sent to a virtual server configured with a Client SSL profile that has session tickets enabled and uses DHE cipher suites. This can cause the Traffic Management Microkernel (TMM) to fail and restart. The impact is limited to the data plane, with no effect on the control plane.
Recommendations
For versions 14.1.0 through 14.1.0.5, consider disabling session tickets in the Client SSL profile or avoiding the use of DHE cipher suites as a temporary workaround until a patch is available. Restrict access to the virtual server configured with the affected Client SSL profile to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
F5 Big-Ip