First published: Mon Mar 19 2018(Updated: )
SSL virtual servers in F5 BIG-IP systems 10.x before 10.2.4 HF9, 11.x before 11.2.1 HF12, 11.3.0 before HF10, 11.4.0 before HF8, 11.4.1 before HF5, 11.5.0 before HF5, and 11.5.1 before HF5, when used with third-party Secure Sockets Layer (SSL) accelerator cards, might allow remote attackers to have unspecified impact via a timing side-channel attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
F5 Big-ip Local Traffic Manager | >=10.0.0<=10.2.4 | |
F5 Big-ip Local Traffic Manager | >=11.0.0<=11.5.1 | |
F5 Big-ip Application Acceleration Manager | >=11.4.0<=11.5.1 | |
F5 BIG-IP Advanced Firewall Manager | >=11.3.0<=11.5.1 | |
F5 BIG-IP Analytics | >=11.0.0<=11.5.1 | |
F5 BIG-IP Access Policy Manager | >=10.1.0<=10.2.4 | |
F5 BIG-IP Access Policy Manager | >=11.0.0<=11.5.1 | |
F5 BIG-IP Application Security Manager | >=10.0.0<=10.2.4 | |
F5 BIG-IP Application Security Manager | >=11.0.0<=11.5.1 | |
F5 Big-ip Edge Gateway | >=10.1.0<=10.2.4 | |
F5 Big-ip Edge Gateway | >=11.0.0<=11.3.0 | |
F5 Big-ip Global Traffic Manager | >=10.0.0<=10.2.4 | |
F5 Big-ip Global Traffic Manager | >=11.0.0<=11.5.1 | |
F5 Big-ip Link Controller | >=10.0.0<=10.2.4 | |
F5 Big-ip Link Controller | >=11.0.0<=11.5.1 | |
F5 Big-ip Policy Enforcement Manager | >=11.3.0<=11.5.1 | |
F5 Big-ip Protocol Security Module | >=10.0.0<=10.2.4 | |
F5 Big-ip Protocol Security Module | >=11.0.0<=11.4.1 | |
F5 Big-ip Webaccelerator | >=10.0.0<=10.2.4 | |
F5 Big-ip Webaccelerator | >=11.0.0<=11.3.0 | |
F5 Big-ip Wan Optimization Manager | >=10.0.0<=10.2.4 | |
F5 Big-ip Wan Optimization Manager | >=11.0.0<=11.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4024 is a vulnerability in SSL virtual servers in F5 BIG-IP systems.
CVE-2014-4024 has a severity rating of 5.9 (medium).
F5 BIG-IP systems 10.x before 10.2.4 HF9, 11.x before 11.2.1 HF12, 11.3.0 before HF10, 11.4.0 before HF8, 11.4.1 before HF5, 11.5.0 before HF5, and 11.5.1 before HF5 are affected by CVE-2014-4024.
There is no known workaround for CVE-2014-4024, it is recommended to apply the necessary updates or patches provided by F5 Networks.
You can find more information about CVE-2014-4024 on the IBM X-Force Exchange and the F5 Networks support website.