Lucene search

K
cve[email protected]CVE-2017-6168
HistoryNov 17, 2017 - 7:29 p.m.

CVE-2017-6168

2017-11-1719:29:00
CWE-203
web.nvd.nist.gov
103
big-ip
vulnerability
cve-2017-6168
ssl
bleichenbacher attack
rsa
mitm attack
robot attack

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

7.4 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

7.2 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

65.9%

On BIG-IP versions 11.6.0-11.6.2 (fixed in 11.6.2 HF1), 12.0.0-12.1.2 HF1 (fixed in 12.1.2 HF2), or 13.0.0-13.0.0 HF2 (fixed in 13.0.0 HF3) a virtual server configured with a Client SSL profile may be vulnerable to an Adaptive Chosen Ciphertext attack (AKA Bleichenbacher attack) against RSA, which when exploited, may result in plaintext recovery of encrypted messages and/or a Man-in-the-middle (MiTM) attack, despite the attacker not having gained access to the server’s private key itself, aka a ROBOT attack.

Affected configurations

NVD
Node
f5big-ip_ltmRange11.6.011.6.2
OR
f5big-ip_ltmRange12.0.012.1.2
OR
f5big-ip_ltmMatch13.0.0
Node
f5big-ip_application_acceleration_managerRange11.6.011.6.2
OR
f5big-ip_application_acceleration_managerRange12.0.012.1.2
OR
f5big-ip_application_acceleration_managerMatch13.0.0
Node
f5big-ip_afmRange11.6.011.6.2
OR
f5big-ip_afmRange12.0.012.1.2
OR
f5big-ip_afmMatch13.0.0
Node
f5big-ip_analyticsRange11.6.011.6.2
OR
f5big-ip_analyticsRange12.0.012.1.2
OR
f5big-ip_analyticsMatch13.0.0
Node
f5big-ip_apmRange11.6.011.6.2
OR
f5big-ip_apmRange12.0.012.1.2
OR
f5big-ip_apmMatch13.0.0
Node
f5big-ip_asmRange11.6.011.6.2
OR
f5big-ip_asmRange12.0.012.1.2
OR
f5big-ip_asmMatch13.0.0
Node
f5big-ip_link_controllerRange11.6.011.6.2
OR
f5big-ip_link_controllerRange12.0.012.1.2
OR
f5big-ip_link_controllerMatch13.0.0
Node
f5big-ip_pemRange11.6.011.6.2
OR
f5big-ip_pemRange12.0.012.1.2
OR
f5big-ip_pemMatch13.0.0
Node
f5websafeRange12.0.012.1.2
OR
f5websafeMatch11.6.2
OR
f5websafeMatch13.0.0

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

7.4 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

7.2 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

65.9%