CVE-2016-9244
published 2017-02-09CVE-2016-9244: A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may leak up to 31 bytes of uninitialized…
PriorityP271high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EXPLOIT
EPSS
74.00%
99.4th percentile
A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may leak up to 31 bytes of uninitialized memory. A remote attacker may exploit this vulnerability to obtain Secure Sockets Layer (SSL) session IDs from other sessions. It is possible that other data from uninitialized memory may be returned as well.
Affected
125 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip_aam | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_advanced_firewall_manager | — | — |
| f5 | big-ip_advanced_firewall_manager | — | — |
| f5 | big-ip_advanced_firewall_manager | — | — |
| f5 | big-ip_advanced_firewall_manager | — | — |
| f5 | big-ip_advanced_firewall_manager | — | — |
| f5 | big-ip_advanced_firewall_manager | — | — |
| f5 | big-ip_advanced_firewall_manager | — | — |
| f5 | big-ip_advanced_firewall_manager | — | — |
| f5 | big-ip_advanced_firewall_manager | — | — |
| f5 | big-ip_advanced_firewall_manager | — | — |
| f5 | big-ip_advanced_firewall_manager | — | — |
Detection & IOCsextracted from sources · hover to see the quote
snort↗
41547
snort↗
41548
- →Detect Ticketbleed exploitation by monitoring for TLS ClientHello messages that include both a Session Ticket extension (non-empty ticket data) and a short/padded Session ID (e.g., a single-byte session ID such as 'A'), which is the attacker-controlled trigger for leaking uninitialized memory. ↗
- →Monitor for TLS ServerHello responses from F5 BIG-IP devices returning a session_id longer than the session_id submitted by the client — up to 31 extra bytes — which indicates successful memory leakage. ↗
- →A high volume of repeated TLS handshake requests to the same F5 BIG-IP SSL virtual server (port 443 or 8443) with Session Ticket extensions may indicate an active Ticketbleed memory harvesting attempt, as exploitation requires a significant number of requests. ↗
- →Focus detection on F5 BIG-IP devices running versions 11.4.0 through 11.6.1 and 12.0.0 with Client SSL profiles where the Session Tickets option is enabled (non-default). ↗
- ·The vulnerability is only exploitable when the non-default 'Session Tickets' option is explicitly enabled in the Client SSL profile on a BIG-IP virtual server. Devices with the default configuration (Session Tickets disabled) are not affected. ↗
- ·The attacker cannot predict or control the contents of the leaked memory, limiting the reliability of targeted data extraction. ↗
- ·Snort rules 41547 and 41548 may be updated; always refer to the FireSIGHT Management Center or Snort.org for the most current rule versions. ↗
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5855-8rvh-x38f: A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may leak up to 31 bytes of uninit
ghsa_unreviewed·2022-05-14
CVE-2016-9244 [HIGH] CWE-200 GHSA-5855-8rvh-x38f: A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may leak up to 31 bytes of uninit
A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may leak up to 31 bytes of uninitialized memory. A remote attacker may exploit this vulnerability to obtain Secure Sockets Layer (SSL) session IDs from other sessions. It is possible that other data from uninitialized memory may be returned as well.
F5
CVE-2016-9244: A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled ...
vendor_f5·2017-02-09·CVSS 7.5
CVE-2016-9244 [HIGH] CWE-200 CVE-2016-9244: A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled ...
CVE-2016-9244: A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled ...
A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may leak up to 31 bytes of uninitialized memory. A remote attacker may exploit this vulnerability to obtain Secure Sockets Layer (SSL) session IDs from other sessions. It is possible that other data from uninitialized memory may be returned as well.
Affected Products: BIG-IP AAM, BIG-IP AFM, BIG-IP APM, BIG-IP ASM, BIG-IP Analytics, BIG-IP GTM, BIG-IP LTM, BIG-IP Link Controller, BIG-IP PEM, Big-Ip Protocol Security Module
Affected Versions: 11.4.0; 11.4.1; 11.5.0; 11.5.1; 11.5.2; 11.5.3; 11.5.4; 11.6.0; 11.6.1; 12.0.0
F5 Advisory Articles
No detection rules found.
Exploit-DB
F5 BIG-IP 11.6 SSL Virtual Server - 'Ticketbleed' Memory Disclosure
exploitdb·2017-02-14·CVSS 7.5
CVE-2016-9244 [HIGH] F5 BIG-IP 11.6 SSL Virtual Server - 'Ticketbleed' Memory Disclosure
F5 BIG-IP 11.6 SSL Virtual Server - 'Ticketbleed' Memory Disclosure
---
# -*- coding: utf-8 -*-
#!/usr/bin/python
# Exploit Title: Ticketbleed
# Google Dork: n/a
# Date: Exploit: 02/13/17, Advisory Published: 02/09/17
# Exploit Author: @0x00string
# Vendor Homepage: https://f5.com/
# Software Link: https://support.f5.com/csp/article/K05121675
# Version: see software link for versions
# Tested on: F5 BIGIP 11.6
# CVE : CVE-2016-9244
# require: scapy_ssl_tls (https://github.com/tintinweb/scapy-ssl_tls)
import re, getopt, sys, socket
from struct import *
try:
from scapy_ssl_tls.ssl_tls import *
except ImportError:
from scapy.layers.ssl_tls import *
def banner():
print '''
lol ty filippo!
ty tintinweb!
0000000000000
0000000000000000000 00
00000000000000000000000000000
0000000000000000000000
Exploit-DB
F5 BIG-IP SSL Virtual Server - 'Ticketbleed' Memory Disclosure
exploitdb·2017-02-10·CVSS 7.5
CVE-2016-9244 [HIGH] F5 BIG-IP SSL Virtual Server - 'Ticketbleed' Memory Disclosure
F5 BIG-IP SSL Virtual Server - 'Ticketbleed' Memory Disclosure
---
/*
# Exploit Title: [Ticketbleed (CVE-2016-9244) F5 BIG-IP SSL virtual server Memory Leakage]
# Date: [10.02.2017]
# Exploit Author: [Ege Balcı]
# Vendor Homepage: [https://f5.com/]
# Version: [12.0.0 - 12.1.2 && 11.4.0 - 11.6.1]
# Tested on: [Multiple]
# CVE : [CVE-2016-9244]
BUILD:
go get github.com/EgeBalci/Ticketbleed
go build Ticketbleed.go
USAGE:
./ticketbleed
OPTIONS:
-o, --out Output filename for raw memory
-s, --size Size in bytes to read
-h, --help Print this message
*/
package main
import "github.com/EgeBalci/Ticketbleed"
import "strconv"
import "strings"
import "fmt"
import "os"
var OutputFile string = ""
var BleedSize int = 0
func main() {
ARGS := os.Args[1:]
if len(ARGS) 5{
fmt.Println(Help)
os.Ex
Talos
Cisco Coverage for 'Ticketbleed'
blogs_talos·2017-02-10·CVSS 7.5
CVE-2016-9244 [HIGH] Cisco Coverage for 'Ticketbleed'
## Vulnerability DetailsA vulnerability (CVE-2016-9244) was recently disclosed affecting various F5 products due to the way in which the products handle Session IDs when the non-default Session Tickets option is enabled. By manipulating the Session IDs provided to affected products, an attacker could potentially leak up to 31 bytes of uninitialized memory. This vulnerability can be used to retrieve potentially sensitive information from affected devices such as SSL session IDs from other sessions, or the contents of uninitialized memory.
It is important to note that the number of bytes returned in the Ticketbleed attack is small (up to 31 bytes). This means that it would likely take a significant number of requests to successfully obtain sensitive information. Also, it does not appear tha
Talos
Cisco Coverage for 'Ticketbleed'
blogs_talos·2017-02-10·CVSS 7.5
CVE-2016-9244 [HIGH] Cisco Coverage for 'Ticketbleed'
## Cisco Coverage for 'Ticketbleed'
## Vulnerability Details A vulnerability (CVE-2016-9244) was recently disclosed affecting various F5 products due to the way in which the products handle Session IDs when the non-default Session Tickets option is enabled. By manipulating the Session IDs provided to affected products, an attacker could potentially leak up to 31 bytes of uninitialized memory. This vulnerability can be used to retrieve potentially sensitive information from affected devices such as SSL session IDs from other sessions, or the contents of uninitialized memory.
It is important to note that the number of bytes returned in the Ticketbleed attack is small (up to 31 bytes). This means that it would likely take a significant number of requests to successfully obtain sensitive inf
http://packetstormsecurity.com/files/141017/Ticketbleed-F5-TLS-Information-Disclosure.htmlhttp://www.securityfocus.com/bid/96143http://www.securitytracker.com/id/1037800https://blog.filippo.io/finding-ticketbleed/https://filippo.io/Ticketbleed/https://github.com/0x00string/oldays/blob/master/CVE-2016-9244.pyhttps://support.f5.com/csp/article/K05121675https://www.exploit-db.com/exploits/41298/http://packetstormsecurity.com/files/141017/Ticketbleed-F5-TLS-Information-Disclosure.htmlhttp://www.securityfocus.com/bid/96143http://www.securitytracker.com/id/1037800https://blog.filippo.io/finding-ticketbleed/https://filippo.io/Ticketbleed/https://github.com/0x00string/oldays/blob/master/CVE-2016-9244.pyhttps://support.f5.com/csp/article/K05121675https://www.exploit-db.com/exploits/41298/
2017-02-09
Published