imPC@ndo IT

Tracker / CVE-2019-6629

CVE-2019-6629

High 7.5

On BIG-IP 14.1.0-14.1.0.5, undisclosed SSL traffic to a virtual server configured with a Client SSL profile may cause TMM to fail and restart. The Client SSL profile must have session tickets enabled and use DHE cipher suites to be affected. This only impacts the data plane, there is no impact to the control plane.

Affected products and versions

f5 big-ip_access_policy_manager · 14.1.0.1 → 14.1.0.5
f5 big-ip_advanced_firewall_manager · 14.1.0.1 → 14.1.0.5
f5 big-ip_analytics · 14.1.0.1 → 14.1.0.5
f5 big-ip_application_acceleration_manager · 14.1.0.1 → 14.1.0.5
f5 big-ip_application_security_manager · 14.1.0.1 → 14.1.0.5
f5 big-ip_domain_name_system · 14.1.0.1 → 14.1.0.5
f5 big-ip_edge_gateway · 14.1.0.1 → 14.1.0.5
f5 big-ip_global_traffic_manager · 14.1.0.1 → 14.1.0.5
f5 big-ip_link_controller · 14.1.0.1 → 14.1.0.5
f5 big-ip_local_traffic_manager · 14.1.0.1 → 14.1.0.5
f5 big-ip_policy_enforcement_manager · 14.1.0.1 → 14.1.0.5
f5 big-ip_webaccelerator · 14.1.0.1 → 14.1.0.5
f5 big-ip_websafe · 14.1.0.1 → 14.1.0.5

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References