Forum Discussion

Sven_Leupold_85's avatar
Jun 05, 2014

SSL/TLS MITM vulnerability (CVE-2014-0224)

Hi folks

 

Did someone get already an official statement from F5 Networks about the latest vulnerability disclosed today? (not heartbleed!)

 

http://www.openssl.org/news/secadv_20140605.txt

 

Thanks for your reply

 

Sven

 

7 Replies

    • Michael_Kenned1's avatar
      Michael_Kenned1
      Icon for Nimbostratus rankNimbostratus
      This tool released by redhat is indicating that my F5 sites (which don't use COMPAT ciphers) are affected: https://access.redhat.com/labs/ccsinjectiontest/ I'm eager to hear F5's official response.
    • Sven_Leupold_85's avatar
      Sven_Leupold_85
      Icon for Cirrus rankCirrus
      Hello Team, Good Morning. Regarding OpenSSL vulnerability - CVE-2014-0224, F5 Product Development has now assigned ID 465799 (BIG-IP) to this vulnerability. To read more about this vulnerability for versions know to be vulnerable and not vulnerable, please see SOL15325 via the link below. We received a case closed message from F5 pointing to SOL15325: OpenSSL vulnerability - CVE-2014-0224 https://support.f5.com/kb/en-us/solutions/public/15000/300/sol15325.html
  • RedHat OpenSSL CCS Injection Vulnerability tool (CVE-2014-0224) https://access.redhat.com/labs/ccsinjectiontest identified VS on F5 (v.10.5.0 & v.10.5.1) as "Status: Vulnerable!"

     

    • Sven_Leupold_85's avatar
      Sven_Leupold_85
      Icon for Cirrus rankCirrus
      Same here, but as F5 does not use openssl stack here, I think that this could be a false positive.