CVE-2017-6168
On BIG-IP versions 11.6.0-11.6.2 (fixed in 11.6.2 HF1), 12.0.0-12.1.2 HF1 (fixed in 12.1.2 HF2), or 13.0.0-13.0.0 HF2 (fixed in 13.0.0 HF3) a virtual server configured with a Client SSL profile may be vulnerable to an Adaptive Chosen Ciphertext attack (AKA Bleichenbacher attack) against RSA, which when exploited, may result in plaintext recovery of encrypted messages and/or a Man-in-the-middle (MiTM) attack, despite the attacker not having gained access to the server's private key itself, aka a ROBOT attack.
Published:Nov 17, 2017
Last Modified:Apr 20, 2025
EPS:Nov 17, 2017
EPSS Score:0.68107
CVSS Score:7.4
Affected Products
Vendor
Product
Action
Vendor
F5
Product
Big-ip Afm
F5
Big-ip Afm
Vendor
F5
Product
Big-ip Analytics
F5
Big-ip Analytics
Vendor
F5
Product
Big-ip Apm
F5
Big-ip Apm
Vendor
F5
Product
Big-ip Application Acceleration Manager
F5
Big-ip Application Acceleration Manager
Vendor
F5
Product
Big-ip Asm
F5
Big-ip Asm
Vendor
F5
Product
Big-ip Link Controller
F5
Big-ip Link Controller
Vendor
F5
Product
Big-ip Ltm
F5
Big-ip Ltm
Vendor
F5
Product
Big-ip Pem
F5
Big-ip Pem
Vendor
F5
Product
Websafe
F5
Websafe
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
