CVE-2014-8730 describes a padding-oracle vulnerability in the SSL profiles component of various F5 BIG-IP products, including LTM, APM, and ASM, when using TLS 1.x before TLS 1.2. This flaw allows man-in-the-middle attackers to decrypt cleartext data due to improper checking of CBC padding bytes. With a CVSS score of 4.3, this vulnerability has a medium attack complexity and could lead to partial confidentiality impact. While there are no known public exploits or Metasploit modules, the vulnerability has garnered community discussion and media coverage, indicating awareness of the issue. This specific CVE is limited to F5's implementation and is not a flaw in the TLS 1.x protocol itself.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.0.0CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_local_traffic_manager:10.0.0:*:*:*:*:*:*:* | ||
10.0.1CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_local_traffic_manager:10.0.1:*:*:*:*:*:*:* | ||
10.1.0CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_local_traffic_manager:10.1.0:*:*:*:*:*:*:* | ||
10.2.0CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_local_traffic_manager:10.2.0:*:*:*:*:*:*:* | ||
10.2.1CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_local_traffic_manager:10.2.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.