CVE Vulnerabilities

CVE-2021-22981

Published: Feb 12, 2021 | Modified: Nov 21, 2024
CVSS 3.x
4.8
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

On all versions of BIG-IP 12.1.x and 11.6.x, the original TLS protocol includes a weakness in the master secret negotiation that is mitigated by the Extended Master Secret (EMS) extension defined in RFC 7627. TLS connections that do not use EMS are vulnerable to man-in-the-middle attacks during renegotiation. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

Affected Software

NameVendorStart VersionEnd Version
Big-ip_access_policy_managerF511.6.1 (including)11.6.5 (including)
Big-ip_access_policy_managerF512.1.0 (including)12.1.5 (including)
Big-ip_advanced_firewall_managerF511.6.1 (including)11.6.5 (including)
Big-ip_advanced_firewall_managerF512.1.0 (including)12.1.5 (including)
Big-ip_advanced_web_application_firewallF511.6.1 (including)11.6.5 (including)
Big-ip_advanced_web_application_firewallF512.1.0 (including)12.1.5 (including)
Big-ip_analyticsF511.6.1 (including)11.6.5 (including)
Big-ip_analyticsF512.1.0 (including)12.1.5 (including)
Big-ip_application_acceleration_managerF511.6.1 (including)11.6.5 (including)
Big-ip_application_acceleration_managerF512.1.0 (including)12.1.5 (including)
Big-ip_application_security_managerF511.6.1 (including)11.6.5 (including)
Big-ip_application_security_managerF512.1.0 (including)12.1.5 (including)
Big-ip_ddos_hybrid_defenderF511.6.1 (including)11.6.5 (including)
Big-ip_ddos_hybrid_defenderF512.1.0 (including)12.1.5 (including)
Big-ip_domain_name_systemF511.6.1 (including)11.6.5 (including)
Big-ip_domain_name_systemF512.1.0 (including)12.1.5 (including)
Big-ip_fraud_protection_serviceF511.6.1 (including)11.6.5 (including)
Big-ip_fraud_protection_serviceF512.1.0 (including)12.1.5 (including)
Big-ip_global_traffic_managerF511.6.1 (including)11.6.5 (including)
Big-ip_global_traffic_managerF512.1.0 (including)12.1.5 (including)
Big-ip_link_controllerF511.6.1 (including)11.6.5 (including)
Big-ip_link_controllerF512.1.0 (including)12.1.5 (including)
Big-ip_local_traffic_managerF511.6.1 (including)11.6.5 (including)
Big-ip_local_traffic_managerF512.1.0 (including)12.1.5 (including)
Big-ip_policy_enforcement_managerF511.6.1 (including)11.6.5 (including)
Big-ip_policy_enforcement_managerF512.1.0 (including)12.1.5 (including)
Big-ip_ssl_orchestratorF511.6.1 (including)11.6.5 (including)
Big-ip_ssl_orchestratorF512.1.0 (including)12.1.5 (including)

References