Rapid7 Vulnerability & Exploit Database

F5 Networks: K05121675 (CVE-2016-9244): F5 TLS vulnerability CVE-2016-9244

Back to Search

F5 Networks: K05121675 (CVE-2016-9244): F5 TLS vulnerability CVE-2016-9244

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
Published
02/08/2017
Created
07/25/2018
Added
02/16/2017
Modified
05/05/2019

Description

A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may leak up to 31 bytes of uninitialized memory. A remote attacker may exploit this vulnerability to obtain Secure Sockets Layer (SSL) session IDs from other sessions. It is possible that other data from uninitialized memory may be returned as well.

Solution(s)

  • f5-big-ip-upgrade-latest

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;