CVE-2021-22981
published 2021-02-12CVE-2021-22981: On all versions of BIG-IP 12.1.x and 11.6.x, the original TLS protocol includes a weakness in the master secret negotiation that is mitigated by the Extended…
PriorityP422medium4.8CVSS 3.1
AVNACHPRNUINSUCLILAN
EPSS
0.54%
41.6th percentile
On all versions of BIG-IP 12.1.x and 11.6.x, the original TLS protocol includes a weakness in the master secret negotiation that is mitigated by the Extended Master Secret (EMS) extension defined in RFC 7627. TLS connections that do not use EMS are vulnerable to man-in-the-middle attacks during renegotiation. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Affected
43 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip_aam | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | 11.6.1 – 11.6.5 | — |
| f5 | big-ip_access_policy_manager | 12.1.0 – 12.1.5 | — |
| f5 | big-ip_advanced_firewall_manager | 11.6.1 – 11.6.5 | — |
| f5 | big-ip_advanced_firewall_manager | 12.1.0 – 12.1.5 | — |
| f5 | big-ip_advanced_waf | — | — |
| f5 | big-ip_advanced_web_application_firewall | 11.6.1 – 11.6.5 | — |
| f5 | big-ip_advanced_web_application_firewall | 12.1.0 – 12.1.5 | — |
| f5 | big-ip_afm | — | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | 11.6.1 – 11.6.5 | — |
| f5 | big-ip_analytics | 12.1.0 – 12.1.5 | — |
| f5 | big-ip_apm | — | — |
| f5 | big-ip_application_acceleration_manager | 11.6.1 – 11.6.5 | — |
| f5 | big-ip_application_acceleration_manager | 12.1.0 – 12.1.5 | — |
| f5 | big-ip_application_security_manager | 11.6.1 – 11.6.5 | — |
| f5 | big-ip_application_security_manager | 12.1.0 – 12.1.5 | — |
| f5 | big-ip_asm | — | — |
| f5 | big-ip_ddos_hybrid_defender | 11.6.1 – 11.6.5 | — |
| f5 | big-ip_ddos_hybrid_defender | 12.1.0 – 12.1.5 | — |
| f5 | big-ip_dhd | — | — |
| f5 | big-ip_dns | — | — |
| f5 | big-ip_domain_name_system | 11.6.1 – 11.6.5 | — |
| f5 | big-ip_domain_name_system | 12.1.0 – 12.1.5 | — |
CVSS provenance
nvdv3.14.8MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q9r3-wvmc-78qp: On all versions of BIG-IP 12
ghsa_unreviewed·2022-05-24
CVE-2021-22981 [MEDIUM] GHSA-q9r3-wvmc-78qp: On all versions of BIG-IP 12
On all versions of BIG-IP 12.1.x and 11.6.x, the original TLS protocol includes a weakness in the master secret negotiation that is mitigated by the Extended Master Secret (EMS) extension defined in RFC 7627. TLS connections that do not use EMS are vulnerable to man-in-the-middle attacks during renegotiation. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
F5
CVE-2021-22981: On all versions of BIG-IP 12
vendor_f5·2021-02-12·CVSS 4.8
CVE-2021-22981 [MEDIUM] CVE-2021-22981: On all versions of BIG-IP 12
CVE-2021-22981: On all versions of BIG-IP 12
On all versions of BIG-IP 12.1.x and 11.6.x, the original TLS protocol includes a weakness in the master secret negotiation that is mitigated by the Extended Master Secret (EMS) extension defined in RFC 7627. TLS connections that do not use EMS are vulnerable to man-in-the-middle attacks during renegotiation. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Affected Products: BIG-IP AAM, BIG-IP AFM, BIG-IP APM, BIG-IP ASM, BIG-IP Advanced WAF, BIG-IP Analytics, BIG-IP DHD, BIG-IP DNS, BIG-IP FPS, BIG-IP GTM, BIG-IP LTM, BIG-IP Link Controller, BIG-IP PEM, BIG-IP SSLO
Affected Versions: 11.6.1 - 11.6.5; 12.1.0 - 12.1.5
F5 Advisory Articles: K09121542
F5 References: https://support.f5.com/csp/artic
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-02-12
Published