CVE-2019-6629
published 2019-07-03CVE-2019-6629: On BIG-IP 14.1.0-14.1.0.5, undisclosed SSL traffic to a virtual server configured with a Client SSL profile may cause TMM to fail and restart. The Client SSL…
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.31%
67.4th percentile
On BIG-IP 14.1.0-14.1.0.5, undisclosed SSL traffic to a virtual server configured with a Client SSL profile may cause TMM to fail and restart. The Client SSL profile must have session tickets enabled and use DHE cipher suites to be affected. This only impacts the data plane, there is no impact to the control plane.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip | — | — |
| f5 | big-ip_aam | — | — |
| f5 | big-ip_access_policy_manager | 14.1.0.1 – 14.1.0.5 | — |
| f5 | big-ip_advanced_firewall_manager | 14.1.0.1 – 14.1.0.5 | — |
| f5 | big-ip_afm | — | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | 14.1.0.1 – 14.1.0.5 | — |
| f5 | big-ip_apm | — | — |
| f5 | big-ip_application_acceleration_manager | 14.1.0.1 – 14.1.0.5 | — |
| f5 | big-ip_application_security_manager | 14.1.0.1 – 14.1.0.5 | — |
| f5 | big-ip_asm | — | — |
| f5 | big-ip_dns | — | — |
| f5 | big-ip_domain_name_system | 14.1.0.1 – 14.1.0.5 | — |
| f5 | big-ip_edge_gateway | — | — |
| f5 | big-ip_edge_gateway | 14.1.0.1 – 14.1.0.5 | — |
| f5 | big-ip_global_traffic_manager | 14.1.0.1 – 14.1.0.5 | — |
| f5 | big-ip_gtm | — | — |
| f5 | big-ip_link_controller | — | — |
| f5 | big-ip_link_controller | 14.1.0.1 – 14.1.0.5 | — |
| f5 | big-ip_local_traffic_manager | 14.1.0.1 – 14.1.0.5 | — |
| f5 | big-ip_ltm | — | — |
| f5 | big-ip_pem | — | — |
| f5 | big-ip_policy_enforcement_manager | 14.1.0.1 – 14.1.0.5 | — |
| f5 | big-ip_webaccelerator | — | — |
| f5 | big-ip_webaccelerator | 14.1.0.1 – 14.1.0.5 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hxpv-6qpq-9fxj: On BIG-IP 14
ghsa_unreviewed·2022-05-24
CVE-2019-6629 [HIGH] GHSA-hxpv-6qpq-9fxj: On BIG-IP 14
On BIG-IP 14.1.0-14.1.0.5, undisclosed SSL traffic to a virtual server configured with a Client SSL profile may cause TMM to fail and restart. The Client SSL profile must have session tickets enabled and use DHE cipher suites to be affected. This only impacts the data plane, there is no impact to the control plane.
F5
CVE-2019-6629: On BIG-IP 14
vendor_f5·2019-07-03·CVSS 7.5
CVE-2019-6629 [HIGH] CVE-2019-6629: On BIG-IP 14
CVE-2019-6629: On BIG-IP 14
On BIG-IP 14.1.0-14.1.0.5, undisclosed SSL traffic to a virtual server configured with a Client SSL profile may cause TMM to fail and restart. The Client SSL profile must have session tickets enabled and use DHE cipher suites to be affected. This only impacts the data plane, there is no impact to the control plane.
Affected Products: BIG-IP AAM, BIG-IP AFM, BIG-IP APM, BIG-IP ASM, BIG-IP Analytics, BIG-IP DNS, BIG-IP Edge Gateway, BIG-IP GTM, BIG-IP LTM, BIG-IP Link Controller, BIG-IP PEM, BIG-IP WebAccelerator, BIG-IP WebSafe
Affected Versions: 14.1.0.1 - 14.1.0.5
F5 Advisory Articles: K95434410
F5 References: https://support.f5.com/csp/article/K95434410, https://support.f5.com/csp/article/K95434410?utm_source=f5support&%3Butm_medium=RSS
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-07-03
Published