Description
On all versions of BIG-IP 12.1.x and 11.6.x, the original TLS protocol includes a weakness in the master secret negotiation that is mitigated by the Extended Master Secret (EMS) extension defined in RFC 7627. TLS connections that do not use EMS are vulnerable to man-in-the-middle attacks during renegotiation. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_misc
https://support.f5.com/csp/article/K09121542
Scores
CVSS v3
4.8
EPSS
0.0023
EPSS Percentile
45.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Details
Status
published
Products (14)
f5/big-ip_access_policy_manager
11.6.1 - 11.6.5
f5/big-ip_advanced_firewall_manager
11.6.1 - 11.6.5
f5/big-ip_advanced_web_application_firewall
11.6.1 - 11.6.5
f5/big-ip_analytics
11.6.1 - 11.6.5
f5/big-ip_application_acceleration_manager
11.6.1 - 11.6.5
f5/big-ip_application_security_manager
11.6.1 - 11.6.5
f5/big-ip_ddos_hybrid_defender
11.6.1 - 11.6.5
f5/big-ip_domain_name_system
11.6.1 - 11.6.5
f5/big-ip_fraud_protection_service
11.6.1 - 11.6.5
f5/big-ip_global_traffic_manager
11.6.1 - 11.6.5
... and 4 more
Published
Feb 12, 2021
Tracked Since
Feb 18, 2026