

Rewterz Threat Advisory – CVE-2019-10953 – PLC Cycle Time Influences Resource Consumption Vulnerability
April 17, 2019
Rewterz Threat Advisory – Oracle Solaris Multiple Third Party Components Multiple Vulnerabilities
April 17, 2019
Rewterz Threat Advisory – CVE-2019-10953 – PLC Cycle Time Influences Resource Consumption Vulnerability
April 17, 2019
Rewterz Threat Advisory – Oracle Solaris Multiple Third Party Components Multiple Vulnerabilities
April 17, 2019Severity
Medium
Analysis Summary
In BIG-IP an attacker sending specially crafted SSL records to a SSL Virtual Server will cause corruption in the SSL data structures leading to intermittent decrypt BAD_RECORD_MAC errors. Clients will be unable to access the application load balanced by a virtual server with an SSL profile until tmm is restarted.
Impact
Denial of Service
Affected Vendors
F5
Affected Products
- F5 BIG-IP Local Traffic Manager (LTM) 11.x
- F5 BIG-IP Application Security Manager (ASM) 11.x
- F5 BIG-IP Local Traffic Manager (LTM) 12.x
- F5 BIG-IP Application Security Manager (ASM) 12.x
- F5 BIG-IP Local Traffic Manager (LTM) 13.x
- F5 BIG-IP Application Security Manager (ASM) 13.x
- F5 BIG-IP Local Traffic Manager (LTM) 14.x
- F5 TMOS 11.x
- F5 BIG-IP Global Traffic Manager (GTM) 11.x
- F5 BIG-IP Access Policy Manager (APM) 11.x
- F5 BIG-IP Application Acceleration Manager (AAM) 11.x
- F5 BIG-IP Advanced Firewall Manager (AFM) 11.x
- F5 BIG-IP Analytics (AVR) 11.x
- F5 BIG-IP Link Controller 11.x
- F5 BIG-IP Policy Enforcement Manager (PEM) 11.x
- F5 BIG-IP Access Policy Manager (APM) 12.x
- F5 BIG-IP Access Policy Manager (APM) 13.x
- F5 BIG-IP Advanced Firewall Manager (AFM) 12.x
- F5 BIG-IP Advanced Firewall Manager (AFM) 13.x
- F5 TMOS 12.x
- F5 BIG-IP DNS (formerly Global Traffic Manager (GTM)) 12.x
Remediation
Update or upgrade to version 14.0.0.3, 13.1.0.8, 12.1.3.6, 11.6.3.3, or 11.5.7.