CVE-2017-6168 is a critical vulnerability affecting F5 BIG-IP products (versions 11.6.0-11.6.2, 12.0.0-12.1.2 HF1, and 13.0.0-13.0.0 HF2) when configured with a Client SSL profile. This vulnerability, known as an Adaptive Chosen Ciphertext attack (ROBOT attack), allows for plaintext recovery of encrypted messages or a Man-in-the-Middle (MiTM) attack against RSA. It carries a high CVSS score of 7.4, indicating a network-based attack with high impact on confidentiality and integrity, despite high attack complexity. While not listed in CISA's KEV catalog, a Metasploit module exists for scanning this vulnerability, and it has garnered significant community discussion and media coverage, suggesting awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 11.6.0, <= 11.6.2CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_ltm:*:*:*:*:*:*:*:* | ||
>= 12.0.0, <= 12.1.2CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_ltm:*:*:*:*:*:*:*:* | ||
13.0.0CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_ltm:13.0.0:*:*:*:*:*:*:* | ||
>= 11.6.0, <= 11.6.2CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:* | ||
>= 12.0.0, <= 12.1.2CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.