Race Condition in F5 SSL Orchestrator with SNAT Enabled
CVE-2019-6627

5.9MEDIUM

Key Information:

Vendor
F5
Vendor
CVE Published:
3 July 2019

Summary

A race condition vulnerability in the F5 SSL Orchestrator can cause unexpected behavior under specific circumstances. When the SSL Forward Proxy enforces a bypass action for a transparent virtual server with SNAT enabled, it may lead to a restart of the Traffic Management Microkernel (TMM). This occurrence is rare, but it poses risks to the stability of the system's SSL handling capabilities, potentially impacting service continuity for users.

Affected Version(s)

F5 SSL Orchestrator F5 SSL Orchestrator 14.1.0-14.1.0.5

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.