{"id": "CVE-2019-6629", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "
[email protected]", "cvssData": {"version": "2.0", "baseScore": 4.3, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:N/C:N/I:N/A:P", "authentication": "NONE", "integrityImpact": "NONE", "accessComplexity": "MEDIUM", "availabilityImpact": "PARTIAL", "confidentialityImpact": "NONE"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 8.6, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV31": [{"type": "Primary", "source": "
[email protected]", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 7.5, "attackVector": "NETWORK", "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "integrityImpact": "NONE", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "NONE"}, "impactScore": 3.6, "exploitabilityScore": 3.9}]}, "published": "2019-07-03T18:15:10.850", "references": [{"url": "https://support.f5.com/csp/article/K95434410", "tags": ["Vendor Advisory"], "source": "
[email protected]"}, {"url": "https://support.f5.com/csp/article/K95434410?utm_source=f5support&%3Butm_medium=RSS", "source": "
[email protected]"}, {"url": "https://support.f5.com/csp/article/K95434410", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://support.f5.com/csp/article/K95434410?utm_source=f5support&%3Butm_medium=RSS", "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "
[email protected]", "description": [{"lang": "en", "value": "NVD-CWE-noinfo"}]}], "descriptions": [{"lang": "en", "value": "On BIG-IP 14.1.0-14.1.0.5, undisclosed SSL traffic to a virtual server configured with a Client SSL profile may cause TMM to fail and restart. The Client SSL profile must have session tickets enabled and use DHE cipher suites to be affected. This only impacts the data plane, there is no impact to the control plane."}, {"lang": "es", "value": "En BIG-IP 14.1.0-14.1.0.5, el tr\u00e1fico SSL no difundido a un servidor virtual configurado con un perfil SSL del Cliente puede hacer que TMM falle y se reinicie. El perfil SSL del cliente debe tener habilitados los tickets de sesi\u00f3n y utilizar los conjuntos de cifrado DHE para verse afectado. Esto solo afecta al plano de datos, no hay impacto en el plano de control."}], "lastModified": "2024-11-21T04:46:50.453", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "869AE209-8219-4530-8083-47431621A57C", "versionEndIncluding": "14.1.0.5", "versionStartIncluding": "14.1.0.1"}], "operator": "OR"}]}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C15011F9-D396-4EA2-96EE-653FC245E6F1", "versionEndIncluding": "14.1.0.5", "versionStartIncluding": "14.1.0.1"}], "operator": "OR"}]}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "980179DE-B521-47B8-A2BE-9F50F66015D5", "versionEndIncluding": "14.1.0.5", "versionStartIncluding": "14.1.0.1"}], "operator": "OR"}]}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "91EA2A3C-2CAA-42FE-8373-03950299A11B", "versionEndIncluding": "14.1.0.5", "versionStartIncluding": "14.1.0.1"}], "operator": "OR"}]}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "00725CB0-1122-4445-842B-D89BC3A7CECC", "versionEndIncluding": "14.1.0.5", "versionStartIncluding": "14.1.0.1"}], "operator": "OR"}]}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7F1C5AE3-CFB2-4C8A-A05D-5AC506D73566", "versionEndIncluding": "14.1.0.5", "versionStartIncluding": "14.1.0.1"}], "operator": "OR"}]}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "321BCABC-7DCF-4167-AFC9-AA4568D57230", "versionEndIncluding": "14.1.0.5", "versionStartIncluding": "14.1.0.1"}], "operator": "OR"}]}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:f5:big-ip_edge_gateway:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "085697D1-CB2F-4830-8C12-CB48E7CFB26C", "versionEndIncluding": "14.1.0.5", "versionStartIncluding": "14.1.0.1"}], "operator": "OR"}]}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1AD07792-602E-41C0-9283-4E03CF3412D2", "versionEndIncluding": "14.1.0.5", "versionStartIncluding": "14.1.0.1"}], "operator": "OR"}]}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "027183AE-6D96-4CE2-9255-4531EB7C6CED", "versionEndIncluding": "14.1.0.5", "versionStartIncluding": "14.1.0.1"}], "operator": "OR"}]}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9868BB36-9BC9-44EE-B51D-E48C89B37A4F", "versionEndIncluding": "14.1.0.5", "versionStartIncluding": "14.1.0.1"}], "operator": "OR"}]}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0C421726-0832-4B82-9CBB-6B272D9F0089", "versionEndIncluding": "14.1.0.5", "versionStartIncluding": "14.1.0.1"}], "operator": "OR"}]}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:f5:big-ip_websafe:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "33D0287B-14EE-415D-9E5C-63FA8542299E", "versionEndIncluding": "14.1.0.5", "versionStartIncluding": "14.1.0.1"}], "operator": "OR"}]}], "sourceIdentifier": "
[email protected]"}