On all versions of BIG-IP 12.1.x and 11.6.x, the original TLS protocol includes a weakness in the master secret negotiation that is mitigated by the Extended Master Secret (EMS) extension defined in RFC 7627. TLS connections that do not use EMS are vulnerable to man-in-the-middle attacks during renegotiation. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: f5

Published: 2021-02-12T17:50:21

Updated: 2024-08-03T18:58:26.095Z

Reserved: 2021-01-06T00:00:00

Link: CVE-2021-22981

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-02-12T18:15:12.797

Modified: 2021-02-19T17:14:08.280

Link: CVE-2021-22981

cve-icon Redhat

No data.