cve/2019/CVE-2019-6593.md

18 lines
1.0 KiB
Markdown
Raw Normal View History

2024-05-26 14:27:05 +02:00
### [CVE-2019-6593](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-6593)
![](https://img.shields.io/static/v1?label=Product&message=BIG-IP%20(LTM%2C%20AAM%2C%20AFM%2C%20Analytics%2C%20APM%2C%20ASM%2C%20DNS%2C%20Edge%20Gateway%2C%20FPS%2C%20GTM%2C%20Link%20Controller%2C%20PEM%2C%20WebAccelerator)&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=Information%20leakage&color=brighgreen)
### Description
On BIG-IP 11.5.1-11.5.4, 11.6.1, and 12.1.0, a virtual server configured with a Client SSL profile may be vulnerable to a chosen ciphertext attack against CBC ciphers. When exploited, this may result in plaintext recovery of encrypted messages through a man-in-the-middle (MITM) attack, despite the attacker not having gained access to the server's private key itself. (CVE-2019-6593 also known as Zombie POODLE and GOLDENDOODLE.)
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/tls-attacker/TLS-Padding-Oracles