CVE-2016-9244
Last modified
CVE-2016-9244 is a vulnerability of currently unknown severity. A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may leak up to 31 bytes of uninitialized memory. A remote attacker may exploit this vulnerability to obtain Secure Sockets Layer (SSL) session IDs from other sessions. EPSS estimates a 74.00% chance of exploitation in the next 30 days.
Description
A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may leak up to 31 bytes of uninitialized memory. A remote attacker may exploit this vulnerability to obtain Secure Sockets Layer (SSL) session IDs from other sessions. It is possible that other data from uninitialized memory may be returned as well.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| F5 | Big-Ip Local Traffic Manager | 11.4.0 |
| F5 | Big-Ip Local Traffic Manager | 11.4.1 |
| F5 | Big-Ip Local Traffic Manager | 11.5.0 |
| F5 | Big-Ip Local Traffic Manager | 11.5.1 |
| F5 | Big-Ip Local Traffic Manager | 11.5.2 |
| F5 | Big-Ip Local Traffic Manager | 11.5.3 |
| F5 | Big-Ip Local Traffic Manager | 11.5.4 |
| F5 | Big-Ip Local Traffic Manager | 11.6.0 |
| F5 | Big-Ip Local Traffic Manager | 11.6.1 |
| F5 | Big-Ip Local Traffic Manager | 12.0.0 |
| F5 | Big-Ip Local Traffic Manager | 12.1.0 |
| F5 | Big-Ip Local Traffic Manager | 12.1.1 |
| F5 | Big-Ip Local Traffic Manager | 12.1.2 |
| F5 | Big-Ip Application Acceleration Manager | 11.4.0 |
| F5 | Big-Ip Application Acceleration Manager | 11.4.1 |
| F5 | Big-Ip Application Acceleration Manager | 11.5.0 |
| F5 | Big-Ip Application Acceleration Manager | 11.5.1 |
| F5 | Big-Ip Application Acceleration Manager | 11.5.2 |
| F5 | Big-Ip Application Acceleration Manager | 11.5.3 |
| F5 | Big-Ip Application Acceleration Manager | 11.5.4 |
| F5 | Big-Ip Application Acceleration Manager | 11.6.0 |
| F5 | Big-Ip Application Acceleration Manager | 11.6.1 |
| F5 | Big-Ip Application Acceleration Manager | 12.0.0 |
| F5 | Big-Ip Application Acceleration Manager | 12.1.0 |
| F5 | Big-Ip Application Acceleration Manager | 12.1.1 |
| F5 | Big-Ip Application Acceleration Manager | 12.1.2 |
| F5 | Big-Ip Advanced Firewall Manager | 11.4.0 |
| F5 | Big-Ip Advanced Firewall Manager | 11.4.1 |
| F5 | Big-Ip Advanced Firewall Manager | 11.5.0 |
| F5 | Big-Ip Advanced Firewall Manager | 11.5.1 |
| F5 | Big-Ip Advanced Firewall Manager | 11.5.2 |
| F5 | Big-Ip Advanced Firewall Manager | 11.5.3 |
| F5 | Big-Ip Advanced Firewall Manager | 11.5.4 |
| F5 | Big-Ip Advanced Firewall Manager | 11.6.0 |
| F5 | Big-Ip Advanced Firewall Manager | 11.6.1 |
| F5 | Big-Ip Advanced Firewall Manager | 12.0.0 |
| F5 | Big-Ip Advanced Firewall Manager | 12.1.0 |
| F5 | Big-Ip Advanced Firewall Manager | 12.1.1 |
| F5 | Big-Ip Advanced Firewall Manager | 12.1.2 |
| F5 | Big-Ip Analytics | 11.4.0 |
| F5 | Big-Ip Analytics | 11.4.1 |
| F5 | Big-Ip Analytics | 11.5.0 |
| F5 | Big-Ip Analytics | 11.5.1 |
| F5 | Big-Ip Analytics | 11.5.2 |
| F5 | Big-Ip Analytics | 11.5.3 |
| F5 | Big-Ip Analytics | 11.5.4 |
| F5 | Big-Ip Analytics | 11.6.0 |
| F5 | Big-Ip Analytics | 11.6.1 |
| F5 | Big-Ip Analytics | 12.0.0 |
| F5 | Big-Ip Analytics | 12.1.0 |
Showing 50 of 115 affected configurations. See NVD for the full list.
References
- http://www.securitytracker.com/id/1037800Third Party Advisory, VDB Entry
- https://support.f5.com/csp/article/K05121675Mitigation, Vendor Advisory
- http://www.securitytracker.com/id/1037800Third Party Advisory, VDB Entry
- https://support.f5.com/csp/article/K05121675Mitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-9244?
How severe is CVE-2016-9244?
How do I fix CVE-2016-9244?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-9238Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2016-9239Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2016-9240Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2016-9241Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2016-9242Multiple SQL injection vulnerabilities in the update method …
- CVE-2016-9243HKDF in cryptography before 1.5.2 returns an empty byte-stri…7.5
- CVE-2016-9245In F5 BIG-IP systems 12.1.0 - 12.1.2, malicious requests mad…
- CVE-2016-9246Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2016-9247Under certain conditions for BIG-IP systems using a virtual …
- CVE-2016-9248Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2016-9249An undisclosed traffic pattern received by a BIG-IP Virtual …
- CVE-2016-9250In F5 BIG-IP 11.2.1, 11.4.0 through 11.6.1, and 12.0.0 throu…
Are you affected by CVE-2016-9244?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
