CVE-2014-8730 Padding issue
Incorrect TLS padding could be accepted when terminating TLS 1.x CBC cipher connections. F5 has fetched CVE-2014-8730 for this issue.
This issue does not affect the management interface, only th...
Published Dec 08, 2014
Version 1.0Jeff_Costlow_10
Historic F5 Account
Joined January 26, 2005
Jeff_Costlow_10
Historic F5 Account
Joined January 26, 2005
LyonsG_85618
Dec 09, 2014Cirrostratus
Jeff - we currently use the following cipher settings:
RC4-SHA:HIGH:MEDIUM:!SSLv2:!SSLv3:!ADH
However according to https://www.ssllabs.com/ssltest/ we are still showing as vulerable.
Any ideas why this woudl be?