F5-K000132686: Medium severity F5 BIG-IP vulnerability
Published Feb 28, 2023
·Updated
The original TLS protocol includes a weakness in master secret negotiation, potentially allowing the Triple Handshake Attack that is mitigated by the Extended Master Secret (EMS) extension defined in RFC 7627.
Affected Software
10 affected componentsFixes available
F5 BIG-IP>=17.0.0<=17.1.0
17.1.0.1
F5 BIG-IP>=16.1.0<=16.1.5
F5 BIG-IP>=15.1.0<=15.1.10
F5 BIG-IP>=14.1.0<=14.1.5
F5 BIG-IP>=13.1.0<=13.1.5
F5 BIG-IQ Centralized Management>=8.0.0<=8.4.0
8.4.1
F5 BIG-IQ Centralized Management=7.1.0
F5 F5OS-A=1.4.0, >=1.3.0<=1.3.2
1.5.0
F5 F5OS-C>=1.5.0<=1.5.1, >=1.3.0<=1.3.2
1.6.0
F5 Traffix SDC=5.1.0
5.2.0
Event History
Feb 28, 2023
Advisory Published
via F5·04:16 PM
Data Sourced
via F5·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of F5-K000132686?
F5-K000132686 is classified as a medium severity vulnerability due to the potential for a Triple Handshake Attack.
2
How do I fix F5-K000132686?
To mitigate F5-K000132686, upgrade to the specified versions that include the Extended Master Secret extension.
3
Which products are affected by F5-K000132686?
F5-K000132686 affects multiple versions of F5 BIG-IP, BIG-IQ Centralized Management, and F5OS products.
4
Can F5-K000132686 be exploited remotely?
Yes, F5-K000132686 can be exploited remotely if the vulnerable TLS protocol is in use.
5
What is the main weakness in F5-K000132686?
The main weakness in F5-K000132686 is a flaw in master secret negotiation in the original TLS protocol.