peter bassill · operator
$ cve CVE-2016-9244 JSON

CVE-2016-9244 EXPLOIT

7.5
HIGH · CVSS 3.0 · EPSS 74% (pctl 99)

Patch early

A public exploit exists.

Description

A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may leak up to 31 bytes of uninitialized memory. A remote attacker may exploit this vulnerability to obtain Secure Sockets Layer (SSL) session IDs from other sessions. It is possible that other data from uninitialized memory may be returned as well.

Scoring

CVSS7.5 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS74% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-200
On CISA KEVno
Public exploityes
Published2017-02-09
Last modified2026-06-17

Affected (10)

VendorProduct
f5big-ip access policy manager
f5big-ip advanced firewall manager
f5big-ip analytics
f5big-ip application acceleration manager
f5big-ip application security manager
f5big-ip global traffic manager
f5big-ip link controller
f5big-ip local traffic manager
f5big-ip policy enforcement manager
f5big-ip protocol security module

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD