CVE-2024-23979
published 2024-02-14CVE-2024-23979: When SSL Client Certificate LDAP or Certificate Revocation List Distribution Point (CRLDP) authentication profile is configured on a virtual server…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.34%
26.5th percentile
When SSL Client Certificate LDAP or Certificate Revocation List Distribution Point (CRLDP) authentication profile is configured on a virtual server, undisclosed requests can cause an increase in CPU resource utilization.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Affected
49 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip | >= 15.1.0 < 15.1.9 | 15.1.9 |
| f5 | big-ip | >= 16.1.0 < 16.1.4 | 16.1.4 |
| f5 | big-ip | >= 17.1.0 < 17.1.1 | 17.1.1 |
| f5 | big-ip_aam | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | >= 15.1.0 < 15.1.9 | 15.1.9 |
| f5 | big-ip_access_policy_manager | >= 16.1.0 < 16.1.4 | 16.1.4 |
| f5 | big-ip_advanced_firewall_manager | — | — |
| f5 | big-ip_advanced_firewall_manager | >= 15.1.0 < 15.1.9 | 15.1.9 |
| f5 | big-ip_advanced_firewall_manager | >= 16.1.0 < 16.1.4 | 16.1.4 |
| f5 | big-ip_afm | — | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | >= 15.1.0 < 15.1.9 | 15.1.9 |
| f5 | big-ip_analytics | >= 16.1.0 < 16.1.4 | 16.1.4 |
| f5 | big-ip_apm | — | — |
| f5 | big-ip_application_acceleration_manager | — | — |
| f5 | big-ip_application_acceleration_manager | >= 15.1.0 < 15.1.9 | 15.1.9 |
| f5 | big-ip_application_acceleration_manager | >= 16.1.0 < 16.1.4 | 16.1.4 |
| f5 | big-ip_application_security_manager | — | — |
| f5 | big-ip_application_security_manager | >= 15.1.0 < 15.1.9 | 15.1.9 |
| f5 | big-ip_application_security_manager | >= 16.1.0 < 16.1.4 | 16.1.4 |
| f5 | big-ip_asm | — | — |
| f5 | big-ip_dns | — | — |
| f5 | big-ip_domain_name_system | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
F5
CVE-2024-23979: When SSL Client Certificate LDAP or Certificate Revocation List Distribution Point (CRLDP) authentication profile is ...
vendor_f5·2024-02-14·CVSS 7.5
CVE-2024-23979 [HIGH] CWE-770 CVE-2024-23979: When SSL Client Certificate LDAP or Certificate Revocation List Distribution Point (CRLDP) authentication profile is ...
CVE-2024-23979: When SSL Client Certificate LDAP or Certificate Revocation List Distribution Point (CRLDP) authentication profile is ...
When SSL Client Certificate LDAP or Certificate Revocation List Distribution Point (CRLDP) authentication profile is configured on a virtual server, undisclosed requests can cause an increase in CPU resource utilization.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Affected Products: BIG-IP AAM, BIG-IP AFM, BIG-IP APM, BIG-IP ASM, BIG-IP Analytics, BIG-IP DNS, BIG-IP FPS, BIG-IP GTM, BIG-IP LTM, BIG-IP Link Controller, BIG-IP PEM, BIG-IQ
Affected Versions: 15.1.0 - 15.1.9; 16.1.0 - 16.1.4; 17.1.0; 8.0.0 - 8.3.0
F5 Advisory Articles: K000134516
F5 References: https://my.f5.com/manage/s/article/K0001345
GHSA
GHSA-r527-86h2-vjj6: When SSL Client Certificate LDAP or Certificate Revocation List Distribution Point (CRLDP) authentication profile is configured on a virtual server, u
ghsa_unreviewed·2024-02-14
CVE-2024-23979 [HIGH] CWE-770 GHSA-r527-86h2-vjj6: When SSL Client Certificate LDAP or Certificate Revocation List Distribution Point (CRLDP) authentication profile is configured on a virtual server, u
When SSL Client Certificate LDAP or Certificate Revocation List Distribution Point (CRLDP) authentication profile is configured on a virtual server, undisclosed requests can cause an increase in CPU resource utilization.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-02-14
Published