Skip to main content

F5 Networks BIG-IP Vulnerability

F5 Networks BIG-IP virtual server appliances may be vulnerable to an Adaptive Chosen-Ciphertext attack (ACC, also known as a Bleichenbacher attack) when configured with a Client SSL profile.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

F5 Networks BIG-IP virtual server appliances may be vulnerable to an Adaptive Chosen-Ciphertext attack (ACC, also known as a Bleichenbacher attack) when configured with a Client SSL profile.

Affected platforms

The following platforms are known to be affected:

F5 BIG-IP LTM 12.0.0

ApplianceAffected Versions
F5 Networks BIG-IP LTM13.00, 12.00-12.1.12, 11.6.0-11.6.2
F5 Networks BIG-IP AAM13.00, 12.00-12.1.12, 11.6.0-11.6.2
F5 Networks BIG-IP AFM13.00, 12.00-12.1.12, 11.6.0-11.6.2
F5 Networks BIG-IP Analytics13.00, 12.00-12.1.12, 11.6.0-11.6.2
F5 Networks BIG-IP APM13.00, 12.00-12.1.12, 11.6.0-11.6.2
F5 Networks BIG-IP ASM13.00, 12.00-12.1.12, 11.6.0-11.6.2
F5 Networks BIG-IP DNS13.00, 12.00-12.1.12
F5 Networks BIG-IP GTM11.6.0-11.6.2
F5 Networks BIG-IP Link Controller13.00, 12.00-12.1.12, 11.6.0-11.6.2
F5 Networks BIG-IP PEM13.00, 12.00-12.1.12, 11.6.0-11.6.2
F5 Networks Websafe13.00, 12.00-12.1.12, 11.6.2

Threat details

Exploitation of this may result in a user recovering plaintext versions of encrypted messages or in a Man-in-the-Middle (MitM) attack, despite not having access to the server’s private key. Only Transport Layer Security (TLS) sessions using RSA key exchange are vulnerable. A chosen-ciphertext attack uses ciphertexts and their related decrypted texts to obtain the secret key, by sending nonsensical blocks to be decrypted and analysing the resulting plaintext. The result of this is that not only can messages be decrypted but new messages can be encrypted, affecting the integrity of the messages. An adaptive chosen-ciphertext attack will use the results of previous queries to inform new attempts.

Performing a recovery of the encrypted messages may only allow a user to view the plaintext versions once the session has ended. For a MitM attack to occur, a user would have to generate millions of server requests during the handshake phase of a session before it times out. The limitations on bandwidth and latency, along with the limited window of opportunity makes this attack significantly more difficult to execute.


Remediation steps

Type Step

F5 Networks have advised users to upgrade to a non-vulnerable version of the affected products as it is the only full resolution of the issue.

If a user is unable to upgrade for whatever reason, F5 have also provided partial mitigation guidance (AskF5 K21905460).


Last edited: 17 February 2020 11:30 am