Forum Discussion
F5 High Prio SSLv3 issue CVE-2014-3566 15102014
I am running bigip LTM version 10.2.4 and i believethis version is vulnerable to the MIM cuz of which i was adviced to switch over to TLS
My questions are
1) Does it apply to both client and server profiles 2)how can i elimiate it 3) And would there be any impact to my existing application if i move over to TLS
Please help
9 Replies
- Abi80_167352
Nimbostratus
thanks for the reply shaggy
Is it applciable to both client and server profiles
- Abi80_167352
Nimbostratus
anyone please help
- shaggy
Nimbostratus
The solution is applicable to both client-side and server-side profiles.
https://devcentral.f5.com/articles/cve-2014-3566-removing-sslv3-from-big-ip
"If you are running 11.5.0 or later, your default clientssl and serverssl profiles do not contain SSLv3 ciphers and SSLv3 cannot be negotiated. If your SSL profile derives from these profiles, your application is not vulnerable. On all versions, you can disable SSLv3 ciphers by adding the string “!SSLv3” to your clienssl or serverssl profile. The procedure to change your ciphers is well described in SOL 13171."
- Amit_Karnik
Nimbostratus
We had a environment where it was not possible to update the client which was running SSL 3.0 but was possible to update the ciphers via a configuration file. A mitigation in such a situation is to disable the CBC based ciphers and leave SSL 3.0 enabled.
Note that this will mitigate CVC-2014-3566 but may be weaker if you have other weaker ciphers. Just an option in case disabling SSL 3.0 is not possible due to other constraints.
- Abi80_167352
Nimbostratus
but if i disable SSL v3 is it unsecured
- Amit_Karnik_269
Nimbostratus
Disabling SSL 3.0 is good. Allow only TLS 1.0+
- Abi80_167352
Nimbostratus
ok we have few applications on sharepoint
So if i move it to TLS1.2 will the users be imapacted sicne we also have few i rules which are defined
- Amit_Karnik_269
Nimbostratus
You will have to test it out. You could enable a specific clientssl profile for specific source IP addresses using an irule in CLIENT_ACCEPTED. This way you could test your new profile on the same VS. Simple would be to create a new VS and verify.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com