CVE-2019-6593: Medium severity f5 access policy manager vulnerability
On BIG-IP 11.5.1-11.5.4, 11.6.1, and 12.1.0, a virtual server configured with a Client SSL profile may be vulnerable to a chosen ciphertext attack against CBC ciphers. When exploited, this may result in plaintext recovery of encrypted messages through a man-in-the-middle (MITM) attack, despite the attacker not having gained access to the server's private key itself. (CVE-2019-6593 also known as Zombie POODLE and GOLDENDOODLE.)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-6593?
CVE-2019-6593 has a severity rating that indicates a significant risk of a man-in-the-middle attack allowing plaintext recovery of encrypted messages.
How do I fix CVE-2019-6593?
To fix CVE-2019-6593, upgrade your affected F5 BIG-IP product to a version that addresses this vulnerability, specifically 11.5.5 or any later version.
Which versions of F5 BIG-IP are affected by CVE-2019-6593?
CVE-2019-6593 affects F5 BIG-IP versions 11.5.1 to 11.5.4, 11.6.1, and 12.1.0.
What types of attacks can exploit CVE-2019-6593?
CVE-2019-6593 can be exploited via chosen ciphertext attacks using CBC ciphers during SSL communication.
Is CVE-2019-6593 a critical vulnerability?
CVE-2019-6593 is considered critical due to the potential for attackers to recover sensitive plaintext information.