Last Modified: Oct 09, 2025
Affected Product(s):
BIG-IP LTM
Known Affected Versions:
17.5.0, 17.5.1
Fixed In:
17.5.1.2
Opened: May 06, 2025 Severity: 3-Major
BIG-IP accepts certificates with explicit EC parameters enabled and handshakes will be successful.
BIG-IP improperly accepts certificates with explicitly-defined EC params when running in Common Criteria mode.
1. BIG-IP is in CC (Common Criteria) mode 2. BIG-IP has ECC certificates as a Server and/or Clients/Servers interacting with BIG-IP sending ECC certificates with Explicit EC params
None
Added fix to reject certificates with explicit defined ec params by BIG-IP