CVE-2019-6629

HIGH

F5 BIG-IP 14.1.0-14.1.0.5 - Denial of Service via SSL Traffic with Session Tickets and DHE Cipher Suites

Title source: llm
STIX 2.1

Description

On BIG-IP 14.1.0-14.1.0.5, undisclosed SSL traffic to a virtual server configured with a Client SSL profile may cause TMM to fail and restart. The Client SSL profile must have session tickets enabled and use DHE cipher suites to be affected. This only impacts the data plane, there is no impact to the control plane.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
https://support.f5.com/csp/article/K95434410

Scores

CVSS v3 7.5
EPSS 0.0070
EPSS Percentile 72.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (13)
f5/big-ip_access_policy_manager 14.1.0.1 - 14.1.0.5
f5/big-ip_advanced_firewall_manager 14.1.0.1 - 14.1.0.5
f5/big-ip_analytics 14.1.0.1 - 14.1.0.5
f5/big-ip_application_acceleration_manager 14.1.0.1 - 14.1.0.5
f5/big-ip_application_security_manager 14.1.0.1 - 14.1.0.5
f5/big-ip_domain_name_system 14.1.0.1 - 14.1.0.5
f5/big-ip_edge_gateway 14.1.0.1 - 14.1.0.5
f5/big-ip_global_traffic_manager 14.1.0.1 - 14.1.0.5
f5/big-ip_link_controller 14.1.0.1 - 14.1.0.5
f5/big-ip_local_traffic_manager 14.1.0.1 - 14.1.0.5
... and 3 more
Published Jul 03, 2019
Tracked Since Feb 18, 2026