HIGH
BIG-IP SSL Client Certificate LDAP and CRLDP Authentication profiles vulnerability
Published Feb 14, 2024
7.5
HIGHCVSS 3.1
EPSS 0.34%
Description
When SSL Client Certificate LDAP or Certificate Revocation List Distribution Point (CRLDP) authentication profile is configured on a virtual server, undisclosed requests can cause an increase in CPU resource utilization.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Affected products
-
- Version 15.1.0StatusaffectedConstraints<15.1.9
- Version 16.1.0StatusaffectedConstraints<16.1.4
- Version 17.1.0StatusaffectedConstraints<17.1.1
- Version
Configuration 1
OR
- ≥ 15.1.0 · < 15.1.9
- ≥ 16.1.0 · < 16.1.4
- 17.1.0
Configuration 2
- ≥ 8.0.0 · ≤ 8.3.0
Configuration 3
OR
- ≥ 15.1.0 · < 15.1.9
- ≥ 16.1.0 · < 16.1.4
- 17.1.0
Configuration 4
OR
- ≥ 15.1.0 · < 15.1.9
- ≥ 16.1.0 · < 16.1.4
- 17.1.0
Configuration 5
OR
- ≥ 15.1.0 · < 15.1.9
- ≥ 16.1.0 · < 16.1.4
- 17.1.0
Configuration 6
OR
- ≥ 15.1.0 · < 15.1.9
- ≥ 16.1.0 · < 16.1.4
- 17.1.0
Configuration 7
OR
- ≥ 15.1.0 · < 15.1.9
- ≥ 16.1.0 · < 16.1.4
- 17.1.0
Configuration 8
OR
- ≥ 15.1.0 · < 15.1.9
- ≥ 16.1.0 · < 16.1.4
- 17.1.0
Configuration 9
OR
- ≥ 15.1.0 · < 15.1.9
- ≥ 16.1.0 · < 16.1.4
- 17.1.0
Configuration 10
OR
- ≥ 15.1.0 · < 15.1.9
- ≥ 16.1.0 · < 16.1.4
- 17.1.0
Configuration 11
OR
- ≥ 15.1.0 · < 15.1.9
- ≥ 16.1.0 · < 16.1.4
- 17.1.0
Configuration 12
OR
- ≥ 15.1.0 · < 15.1.9
- ≥ 16.1.0 · < 16.1.4
- 17.1.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (1)
- https://my.f5.com/manage/s/article/K000134516 vendor-advisoryVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://my.f5.com/manage/s/article/K000134516 | vendor-advisoryVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner f5
Published Feb 14, 2024
Updated Aug 1, 2024
Reserved Feb 1, 2024
Link CVE-2024-23979
CISA Vulnrichment
Updated Feb 14, 2024