ZeroHour

CVE-2017-6141

CVSS 3.0
5.9 medium
EPSS
1%p63
Published
()
Modified
Description

In F5 BIG-IP LTM, AAM, AFM, APM, ASM, Link Controller, PEM, and WebSafe 12.1.0 through 12.1.2, certain values in a TLS abbreviated handshake when using a client SSL profile with the Session Ticket option enabled may cause disruption of service to the Traffic Management Microkernel (TMM). The Session Ticket option is disabled by default.

Vendors
f5
Products
big-ip access policy manager, big-ip advanced firewall manager, big-ip application acceleration manager, big-ip application security manager, big-ip link controller, big-ip local traffic manager, big-ip policy enforcement manager, big-ip websafe
Weakness
CWE-20
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.