4.3
CVSSv2

CVE-2019-6593

Published: 26/02/2019 Updated: 21/07/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 384
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

On BIG-IP 11.5.1-11.5.4, 11.6.1, and 12.1.0, a virtual server configured with a Client SSL profile may be vulnerable to a chosen ciphertext attack against CBC ciphers. When exploited, this may result in plaintext recovery of encrypted messages through a man-in-the-middle (MITM) attack, despite the attacker not having gained access to the server's private key itself. (CVE-2019-6593 also known as Zombie POODLE and GOLDENDOODLE.)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

f5 big-ip access policy manager 12.1.0

f5 big-ip access policy manager 11.6.1

f5 big-ip access policy manager

f5 big-ip local traffic manager 11.6.1

f5 big-ip local traffic manager 12.1.0

f5 big-ip local traffic manager

f5 big-ip advanced firewall manager 11.6.1

f5 big-ip advanced firewall manager

f5 big-ip advanced firewall manager 12.1.0

f5 big-ip analytics 11.6.1

f5 big-ip analytics 12.1.0

f5 big-ip analytics

f5 big-ip application security manager 11.6.1

f5 big-ip application security manager 12.1.0

f5 big-ip application security manager

f5 big-ip domain name system 11.6.1

f5 big-ip domain name system

f5 big-ip domain name system 12.1.0

f5 big-ip edge gateway 12.1.0

f5 big-ip edge gateway 11.6.1

f5 big-ip edge gateway

f5 big-ip fraud protection service 12.1.0

f5 big-ip fraud protection service 11.6.1

f5 big-ip fraud protection service

f5 big-ip global traffic manager 12.1.0

f5 big-ip global traffic manager

f5 big-ip global traffic manager 11.6.1

f5 big-ip link controller 11.6.1

f5 big-ip link controller

f5 big-ip link controller 12.1.0

f5 big-ip policy enforcement manager 12.1.0

f5 big-ip policy enforcement manager 11.6.1

f5 big-ip policy enforcement manager

f5 big-ip webaccelerator 11.6.1

f5 big-ip webaccelerator 12.1.0

f5 big-ip webaccelerator

Github Repositories

New TLS Padding Oracles

TLS Padding Oracles The TLS protocol provides encryption, data integrity, and authentication on the modern Internet Despite the protocol’s importance, currently-deployed TLS versions use obsolete cryptographic algorithms which have been broken using various attacks One prominent class of such attacks is CBC padding oracle attacks These attacks allow an adversary to dec

New TLS Padding Oracles

TLS Padding Oracles The TLS protocol provides encryption, data integrity, and authentication on the modern Internet Despite the protocol’s importance, currently-deployed TLS versions use obsolete cryptographic algorithms which have been broken using various attacks One prominent class of such attacks is CBC padding oracle attacks These attacks allow an adversary to dec