CVE-2019-6629

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/07/2019
Last modified:
07/11/2023

Description

On BIG-IP 14.1.0-14.1.0.5, undisclosed SSL traffic to a virtual server configured with a Client SSL profile may cause TMM to fail and restart. The Client SSL profile must have session tickets enabled and use DHE cipher suites to be affected. This only impacts the data plane, there is no impact to the control plane.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:* 14.1.0.1 (including) 14.1.0.5 (including)
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:* 14.1.0.1 (including) 14.1.0.5 (including)
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:* 14.1.0.1 (including) 14.1.0.5 (including)
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:* 14.1.0.1 (including) 14.1.0.5 (including)
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* 14.1.0.1 (including) 14.1.0.5 (including)
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:* 14.1.0.1 (including) 14.1.0.5 (including)
cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:* 14.1.0.1 (including) 14.1.0.5 (including)
cpe:2.3:a:f5:big-ip_edge_gateway:*:*:*:*:*:*:*:* 14.1.0.1 (including) 14.1.0.5 (including)
cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:* 14.1.0.1 (including) 14.1.0.5 (including)
cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:* 14.1.0.1 (including) 14.1.0.5 (including)
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:* 14.1.0.1 (including) 14.1.0.5 (including)
cpe:2.3:a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:* 14.1.0.1 (including) 14.1.0.5 (including)
cpe:2.3:a:f5:big-ip_websafe:*:*:*:*:*:*:*:* 14.1.0.1 (including) 14.1.0.5 (including)