CVE-2024-28889 is a medium-severity denial-of-service vulnerability affecting F5 products. It allows an unauthenticated attacker to terminate the Traffic Management Microkernel (TMM) by sending undisclosed traffic to a virtual server configured with a non-default SSL profile alert timeout. The attack requires specific conditions beyond the attacker's control, making exploitation more complex. Currently, there is no public exploit code, active exploitation, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 15.1.0, < 15.1.10.4CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* | ||
>= 15.1.0, < 15.1.10.4CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:* | ||
>= 15.1.0, < 15.1.10.4CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:* | ||
>= 15.1.0, < 15.1.10.4CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:* | ||
>= 15.1.0, < 15.1.10.4CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.