Rapid7 Vulnerability & Exploit Database

F5 Networks: CVE-2020-5929: K91158923: BIG-IP SSL/TLS ADH/DHE vulnerability CVE-2020-5929

Free InsightVM Trial No Credit Card Necessary
2024 Attack Intel Report Latest research by Rapid7 Labs
Back to Search

F5 Networks: CVE-2020-5929: K91158923: BIG-IP SSL/TLS ADH/DHE vulnerability CVE-2020-5929

Severity
3
CVSS
(AV:N/AC:H/Au:N/C:P/I:N/A:N)
Published
09/09/2020
Created
09/12/2020
Added
09/09/2020
Modified
08/23/2024

Description

In versions 13.0.0-13.0.0 HF2, 12.1.0-12.1.2 HF1, and 11.6.1-11.6.2, BIG-IP platforms with Cavium Nitrox SSL hardware acceleration cards, a Virtual Server configured with a Client SSL profile, and using Anonymous (ADH) or Ephemeral (DHE) Diffie-Hellman key exchange and Single DH use option not enabled in the options list may be vulnerable to crafted SSL/TLS Handshakes that may result with a PMS (Pre-Master Secret) that starts in a 0 byte and may lead to a recovery of plaintext messages as BIG-IP TLS/SSL ADH/DHE sends different error messages acting as an oracle. Similar error messages when PMS starts with 0 byte coupled with very precise timing measurement observation may also expose this vulnerability.

Solution(s)

  • f5-big-ip-upgrade-latest

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;