vendor:
BIG-IP
by:
Ege Balci
7.5
CVSS
HIGH
Ticketbleed
125
CWE
Product Name: BIG-IP
Affected Version From: 12.0.0
Affected Version To: 12.1.2 & 11.4.0 - 11.6.1
Patch Exists: YES
Related CWE: CVE-2016-9244
CPE: a:f5:big-ip
Platforms Tested: Multiple
2016
Ticketbleed (CVE-2016-9244) F5 BIG-IP SSL virtual server Memory Leakage
The exploit allows an attacker to read up to 31 bytes of uninitialized memory at a time from a connected client or server.
Mitigation:
Upgrade to a non-vulnerable version of the software (12.1.3 or later for BIG-IP, 11.6.2 or later for BIG-IQ)