F5-K000141313: Low severity f5 traffix systems signaling delivery controller vulnerability
Some non-default TLS server configurations can cause unbounded memory growth when processing TLSv1.3 sessions Impact summary: An attacker may exploit certain server configurations to trigger unbounded memory growth that would lead to a Denial of Service This problem can occur in TLSv1.3 if the non-default SSLOPNOTICKET option is being used (but not if earlydata support is also configured and the default anti-replay protection is in use). In this case, under certain conditions, the session cache can get into an incorrect state and it will fail to flush properly as it fills. The session cache will continue to grow in an unbounded manner. A malicious client could deliberately create the scenario for this failure to force a Denial of Service. It may also happen by accident in normal operation. This issue only affects TLS servers supporting TLSv1.3. It does not affect TLS clients. The FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue. OpenSSL 1.0.2 is also not affected by this issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of F5-K000141313?
The severity of F5-K000141313 is critical due to the potential for Denial of Service caused by unbounded memory growth.
How do I fix F5-K000141313?
To fix F5-K000141313, review and adjust your TLS server configurations to avoid non-default settings that may lead to memory growth.
What types of attacks does F5-K000141313 mitigate against?
F5-K000141313 addresses vulnerabilities that could be exploited to launch Denial of Service attacks through improper TLSv1.3 configurations.
Which versions of F5 Traffix SDC are affected by F5-K000141313?
F5-K000141313 affects F5 Traffix SDC version 5.2.0.
What configurations can lead to vulnerabilities in F5-K000141313?
Non-default TLS server configurations are the primary cause of vulnerabilities outlined in F5-K000141313.