CVE-2016-9244

HIGH

BIG-IP - Memory Corruption

Title source: llm
STIX 2.1

Description

A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may leak up to 31 bytes of uninitialized memory. A remote attacker may exploit this vulnerability to obtain Secure Sockets Layer (SSL) session IDs from other sessions. It is possible that other data from uninitialized memory may be returned as well.

Exploits (4)

exploitdb WORKING POC
by @0x00string · pythonremotehardware
https://www.exploit-db.com/exploits/44446
exploitdb WORKING POC
by Ege Balci · textremotehardware
https://www.exploit-db.com/exploits/41298
nomisec WORKING POC 30 stars
by EgeBalci · poc
https://github.com/EgeBalci/Ticketbleed
nomisec SCANNER
by glestel · poc
https://github.com/glestel/minion-ticket-bleed-plugin

Scores

CVSS v3 7.5
EPSS 0.6747
EPSS Percentile 98.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-200
Status published
Products (50)
f5/big-ip_access_policy_manager 11.4.0
f5/big-ip_access_policy_manager 11.4.1
f5/big-ip_access_policy_manager 11.5.0
f5/big-ip_access_policy_manager 11.5.1
f5/big-ip_access_policy_manager 11.5.2
f5/big-ip_access_policy_manager 11.5.3
f5/big-ip_access_policy_manager 11.5.4
f5/big-ip_access_policy_manager 11.6.0
f5/big-ip_access_policy_manager 11.6.1
f5/big-ip_access_policy_manager 12.0.0
... and 40 more
Published Feb 09, 2017
Tracked Since Feb 18, 2026