VULNERABILITY INTELLIGENCE

CVE-2016-9244

CVSS score7.5 HIGH
EPSS probability74.00%
CISA KEVNot currently listed
Published2017-02-09
Last modified2026-06-17
CVSS vectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may leak up to 31 bytes of uninitialized memory. A remote attacker may exploit this vulnerability to obtain Secure Sockets Layer (SSL) session IDs from other sessions. It is possible that other data from uninitialized memory may be returned as well.

Weakness classification

  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Primary references