CVE-2019-6629

On BIG-IP 14.1.0-14.1.0.5, undisclosed SSL traffic to a virtual server configured with a Client SSL profile may cause TMM to fail and restart. The Client SSL profile must have session tickets enabled and use DHE cipher suites to be affected. This only impacts the data plane, there is no impact to the control plane.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
f5CNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 70%
VendorProductVersion
f5big-ip_local_traffic_manager
14.1.0.1 ≤
𝑥
≤ 14.1.0.5
f5big-ip_application_acceleration_manager
14.1.0.1 ≤
𝑥
≤ 14.1.0.5
f5big-ip_advanced_firewall_manager
14.1.0.1 ≤
𝑥
≤ 14.1.0.5
f5big-ip_analytics
14.1.0.1 ≤
𝑥
≤ 14.1.0.5
f5big-ip_access_policy_manager
14.1.0.1 ≤
𝑥
≤ 14.1.0.5
f5big-ip_application_security_manager
14.1.0.1 ≤
𝑥
≤ 14.1.0.5
f5big-ip_domain_name_system
14.1.0.1 ≤
𝑥
≤ 14.1.0.5
f5big-ip_edge_gateway
14.1.0.1 ≤
𝑥
≤ 14.1.0.5
f5big-ip_global_traffic_manager
14.1.0.1 ≤
𝑥
≤ 14.1.0.5
f5big-ip_link_controller
14.1.0.1 ≤
𝑥
≤ 14.1.0.5
f5big-ip_policy_enforcement_manager
14.1.0.1 ≤
𝑥
≤ 14.1.0.5
f5big-ip_webaccelerator
14.1.0.1 ≤
𝑥
≤ 14.1.0.5
f5big-ip_websafe
14.1.0.1 ≤
𝑥
≤ 14.1.0.5
𝑥
= Vulnerable software versions