CVE Vulnerabilities

CVE-2021-22981

Published: Feb 12, 2021 | Modified: Feb 19, 2021
CVSS 3.x
4.8
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

On all versions of BIG-IP 12.1.x and 11.6.x, the original TLS protocol includes a weakness in the master secret negotiation that is mitigated by the Extended Master Secret (EMS) extension defined in RFC 7627. TLS connections that do not use EMS are vulnerable to man-in-the-middle attacks during renegotiation. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

Affected Software

Name Vendor Start Version End Version
Big-ip_access_policy_manager F5 11.6.1 (including) 11.6.5 (including)
Big-ip_access_policy_manager F5 12.1.0 (including) 12.1.5 (including)
Big-ip_advanced_firewall_manager F5 11.6.1 (including) 11.6.5 (including)
Big-ip_advanced_firewall_manager F5 12.1.0 (including) 12.1.5 (including)
Big-ip_advanced_web_application_firewall F5 11.6.1 (including) 11.6.5 (including)
Big-ip_advanced_web_application_firewall F5 12.1.0 (including) 12.1.5 (including)
Big-ip_analytics F5 11.6.1 (including) 11.6.5 (including)
Big-ip_analytics F5 12.1.0 (including) 12.1.5 (including)
Big-ip_application_acceleration_manager F5 11.6.1 (including) 11.6.5 (including)
Big-ip_application_acceleration_manager F5 12.1.0 (including) 12.1.5 (including)
Big-ip_application_security_manager F5 11.6.1 (including) 11.6.5 (including)
Big-ip_application_security_manager F5 12.1.0 (including) 12.1.5 (including)
Big-ip_ddos_hybrid_defender F5 11.6.1 (including) 11.6.5 (including)
Big-ip_ddos_hybrid_defender F5 12.1.0 (including) 12.1.5 (including)
Big-ip_domain_name_system F5 11.6.1 (including) 11.6.5 (including)
Big-ip_domain_name_system F5 12.1.0 (including) 12.1.5 (including)
Big-ip_fraud_protection_service F5 11.6.1 (including) 11.6.5 (including)
Big-ip_fraud_protection_service F5 12.1.0 (including) 12.1.5 (including)
Big-ip_global_traffic_manager F5 11.6.1 (including) 11.6.5 (including)
Big-ip_global_traffic_manager F5 12.1.0 (including) 12.1.5 (including)
Big-ip_link_controller F5 11.6.1 (including) 11.6.5 (including)
Big-ip_link_controller F5 12.1.0 (including) 12.1.5 (including)
Big-ip_local_traffic_manager F5 11.6.1 (including) 11.6.5 (including)
Big-ip_local_traffic_manager F5 12.1.0 (including) 12.1.5 (including)
Big-ip_policy_enforcement_manager F5 11.6.1 (including) 11.6.5 (including)
Big-ip_policy_enforcement_manager F5 12.1.0 (including) 12.1.5 (including)
Big-ip_ssl_orchestrator F5 11.6.1 (including) 11.6.5 (including)
Big-ip_ssl_orchestrator F5 12.1.0 (including) 12.1.5 (including)

References