On F5 BIG-IP 13.1.0-13.1.0.3, 13.0.0, 12.1.0-12.1.3.3, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, a malformed TLS handshake causes TMM to crash leading to a disruption of service
Published Jun 1, 2018
7.5
HIGHCVSS 3.0
EPSS 1.76%
Description
On F5 BIG-IP 13.1.0-13.1.0.3, 13.0.0, 12.1.0-12.1.3.3, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, a malformed TLS handshake causes TMM to crash leading to a disruption of service. This issue is only exposed on the data plane when Proxy SSL configuration is enabled. The control plane is not impacted by this issue.
Affected products
-
- Version 11.2.1StatusaffectedConstraints-
- Version 11.5.1-11.5.5StatusaffectedConstraints-
- Version 11.6.1-11.6.3.1StatusaffectedConstraints-
- Version 12.1.0-12.1.3.3StatusaffectedConstraints-
- Version 13.0.0StatusaffectedConstraints-
- Version 13.1.0-13.1.0.3StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| F5 Networks, Inc. | n/a | n/a |
|
Configuration 1
- ≥ 11.2.1 · ≤ 11.5.5
- ≥ 11.6.1 · ≤ 11.6.3
- ≥ 12.1.0 · ≤ 12.1.3
- ≥ 13.1.0 · ≤ 13.1.0.4
- 13.0.0
Configuration 2
- ≥ 11.2.1 · ≤ 11.5.5
- ≥ 11.6.1 · ≤ 11.6.3
- ≥ 12.1.0 · ≤ 12.1.3
- ≥ 13.1.0 · ≤ 13.1.0.4
- 13.0.0
Configuration 3
- ≥ 11.2.1 · ≤ 11.5.5
- ≥ 11.6.1 · ≤ 11.6.3
- ≥ 12.1.0 · ≤ 12.1.3
- ≥ 13.1.0 · ≤ 13.1.0.4
- 13.0.0
Configuration 4
- ≥ 11.2.1 · ≤ 11.5.5
- ≥ 11.6.1 · ≤ 11.6.3
- ≥ 12.1.0 · ≤ 12.1.3
- ≥ 13.1.0 · ≤ 13.1.0.4
- 13.0.0
Configuration 5
- ≥ 11.2.1 · ≤ 11.5.5
- ≥ 11.6.1 · ≤ 11.6.3
- ≥ 12.1.0 · ≤ 12.1.3
- ≥ 13.1.0 · ≤ 13.1.0.4
- 13.0.0
Configuration 6
- ≥ 11.2.1 · ≤ 11.5.5
- ≥ 11.6.1 · ≤ 11.6.3
- ≥ 12.1.0 · ≤ 12.1.3
- ≥ 13.1.0 · ≤ 13.1.0.4
- 13.0.0
Configuration 7
- ≥ 11.2.1 · ≤ 11.5.5
- ≥ 11.6.1 · ≤ 11.6.3
- ≥ 12.1.0 · ≤ 12.1.3
- ≥ 13.1.0 · ≤ 13.1.0.4
- 13.0.0
Configuration 8
- ≥ 11.2.1 · ≤ 11.5.5
- ≥ 11.6.1 · ≤ 11.6.3
- ≥ 12.1.0 · ≤ 12.1.3
- ≥ 13.1.0 · ≤ 13.1.0.4
- 13.0.0
Configuration 9
- ≥ 11.2.1 · ≤ 11.5.5
- ≥ 11.6.1 · ≤ 11.6.3
- ≥ 12.1.0 · ≤ 12.1.3
- ≥ 13.1.0 · ≤ 13.1.0.4
- 13.0.0
Configuration 10
- ≥ 11.2.1 · ≤ 11.5.5
- ≥ 11.6.1 · ≤ 11.6.3
- ≥ 12.1.0 · ≤ 12.1.3
- ≥ 13.1.0 · ≤ 13.1.0.4
- 13.0.0
Configuration 11
- ≥ 11.2.1 · ≤ 11.5.5
- ≥ 11.6.1 · ≤ 11.6.3
- ≥ 12.1.0 · ≤ 12.1.3
- ≥ 13.1.0 · ≤ 13.1.0.4
- 13.0.0
Configuration 12
- ≥ 11.2.1 · ≤ 11.5.5
- ≥ 11.6.1 · ≤ 11.6.3
- ≥ 12.1.0 · ≤ 12.1.3
- ≥ 13.1.0 · ≤ 13.1.0.4
- 13.0.0
Configuration 13
- ≥ 11.2.1 · ≤ 11.5.5
- ≥ 11.6.1 · ≤ 11.6.3
- ≥ 12.1.0 · ≤ 12.1.3
- ≥ 13.1.0 · ≤ 13.1.0.4
- 13.0.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- http://www.securitytracker.com/id/1041017 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- https://support.f5.com/csp/article/K46940010 x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.securitytracker.com/id/1041017 | vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry | |
| https://support.f5.com/csp/article/K46940010 | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.