cbcvebase.
CVE-2016-9244
published 2017-02-09

CVE-2016-9244: A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may leak up to 31 bytes of uninitialized…

PriorityP271high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EXPLOIT
EPSS
74.00%
99.4th percentile
A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may leak up to 31 bytes of uninitialized memory. A remote attacker may exploit this vulnerability to obtain Secure Sockets Layer (SSL) session IDs from other sessions. It is possible that other data from uninitialized memory may be returned as well.

Affected

125 ranges· showing 25
VendorProductVersion rangeFixed in
f5big-ip_aam
f5big-ip_access_policy_manager
f5big-ip_access_policy_manager
f5big-ip_access_policy_manager
f5big-ip_access_policy_manager
f5big-ip_access_policy_manager
f5big-ip_access_policy_manager
f5big-ip_access_policy_manager
f5big-ip_access_policy_manager
f5big-ip_access_policy_manager
f5big-ip_access_policy_manager
f5big-ip_access_policy_manager
f5big-ip_access_policy_manager
f5big-ip_access_policy_manager
f5big-ip_advanced_firewall_manager
f5big-ip_advanced_firewall_manager
f5big-ip_advanced_firewall_manager
f5big-ip_advanced_firewall_manager
f5big-ip_advanced_firewall_manager
f5big-ip_advanced_firewall_manager
f5big-ip_advanced_firewall_manager
f5big-ip_advanced_firewall_manager
f5big-ip_advanced_firewall_manager
f5big-ip_advanced_firewall_manager
f5big-ip_advanced_firewall_manager

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://github.com/0x00string/oldays/blob/master/CVE-2016-9244.py
urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/41298.zip
snort
41547
snort
41548
  • Detect Ticketbleed exploitation by monitoring for TLS ClientHello messages that include both a Session Ticket extension (non-empty ticket data) and a short/padded Session ID (e.g., a single-byte session ID such as 'A'), which is the attacker-controlled trigger for leaking uninitialized memory.
  • Monitor for TLS ServerHello responses from F5 BIG-IP devices returning a session_id longer than the session_id submitted by the client — up to 31 extra bytes — which indicates successful memory leakage.
  • A high volume of repeated TLS handshake requests to the same F5 BIG-IP SSL virtual server (port 443 or 8443) with Session Ticket extensions may indicate an active Ticketbleed memory harvesting attempt, as exploitation requires a significant number of requests.
  • Focus detection on F5 BIG-IP devices running versions 11.4.0 through 11.6.1 and 12.0.0 with Client SSL profiles where the Session Tickets option is enabled (non-default).
  • ·The vulnerability is only exploitable when the non-default 'Session Tickets' option is explicitly enabled in the Client SSL profile on a BIG-IP virtual server. Devices with the default configuration (Session Tickets disabled) are not affected.
  • ·The attacker cannot predict or control the contents of the leaked memory, limiting the reliability of targeted data extraction.
  • ·Snort rules 41547 and 41548 may be updated; always refer to the FireSIGHT Management Center or Snort.org for the most current rule versions.

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.