CVE-2019-6629
HIGHF5 BIG-IP 14.1.0-14.1.0.5 - Denial of Service via SSL Traffic with Session Tickets and DHE Cipher Suites
Title source: llmDescription
On BIG-IP 14.1.0-14.1.0.5, undisclosed SSL traffic to a virtual server configured with a Client SSL profile may cause TMM to fail and restart. The Client SSL profile must have session tickets enabled and use DHE cipher suites to be affected. This only impacts the data plane, there is no impact to the control plane.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
https://support.f5.com/csp/article/K95434410
Vendor Advisory x_refsource_confirm
https://support.f5.com/csp/article/K95434410?utm_source=f5support&%3Butm_medium=RSS
Scores
CVSS v3
7.5
EPSS
0.0070
EPSS Percentile
72.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
Status
published
Products (13)
f5/big-ip_access_policy_manager
14.1.0.1 - 14.1.0.5
f5/big-ip_advanced_firewall_manager
14.1.0.1 - 14.1.0.5
f5/big-ip_analytics
14.1.0.1 - 14.1.0.5
f5/big-ip_application_acceleration_manager
14.1.0.1 - 14.1.0.5
f5/big-ip_application_security_manager
14.1.0.1 - 14.1.0.5
f5/big-ip_domain_name_system
14.1.0.1 - 14.1.0.5
f5/big-ip_edge_gateway
14.1.0.1 - 14.1.0.5
f5/big-ip_global_traffic_manager
14.1.0.1 - 14.1.0.5
f5/big-ip_link_controller
14.1.0.1 - 14.1.0.5
f5/big-ip_local_traffic_manager
14.1.0.1 - 14.1.0.5
... and 3 more
Published
Jul 03, 2019
Tracked Since
Feb 18, 2026