Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
SEVERITY: Medium
CATEGORY: Vulnerability
ANALYSIS SUMMARY
During key agreement in a TLS handshake using a DH(E) based ciphersuite, a malicious server can send a very large prime value to the client. This will cause the client to spend an unreasonably long period of time generating a key for this prime resulting in a hang until the client has finished. This could be exploited in a Denial Of Service attack.
AFFECTED PRODUCTS
REMEDIATION
Update to a fixed version that vendor has released.
For BIG-IP LTM 14.0.0 – 14.1.0, Enterprise Manager, BIG-IQ Centralized Management:
No official solution is currently available.
BIG-IP LTM 11.2.1 – 11.6.3, 12.1.0 – 12.1.3, 13.0.0 – 13.1.1:
Update to version 11.6.3.3, 12.1.4, or 13.1.1.2.
BIG-IP AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, FPS, GTM, Link Controller, PEM, WebAccelerator: Update to version 11.6.3.3, 12.1.4, or 13.1.1.2