Lucene search

K
f5F5F5:K000138912
HistoryMay 08, 2024 - 12:00 a.m.

K000138912 : BIG-IP SSL vulnerability CVE-2024-28889

2024-05-0800:00:00
my.f5.com
15
big-ip
ssl
vulnerability
tmm
denial-of-service

AI Score

7.1

Confidence

High

EPSS

0

Percentile

9.0%

Security Advisory Description

When an SSL profile with alert timeout is configured with a non-default value on a virtual server, undisclosed traffic along with conditions beyond the attacker’s control can cause the Traffic Management Microkernel (TMM) to terminate. (CVE-2024-28889)

Impact

Traffic is disrupted while the TMM process restarts. This vulnerability allows a remote unauthenticated attacker to cause a denial-of-service (DoS) on the BIG-IP system. There is no control plane exposure; this is a data plane issue only.

AI Score

7.1

Confidence

High

EPSS

0

Percentile

9.0%