Bug ID 883133: TLS_FALLBACK_SCSV with TLS1.3

Last Modified: Sep 14, 2023

Affected Product(s):
BIG-IP LTM(all modules)

Known Affected Versions:
14.1.2,,,,,,,,, 14.1.3,, 14.1.4,,,,,,, 14.1.5,,,,,, 15.1.0,,,,,, 15.1.1, 15.1.2,, 15.1.3,, 15.1.4,, 15.1.5,, 15.1.6,, 15.1.7, 15.1.8,,

Fixed In:
16.1.0, 15.1.9

Opened: Feb 20, 2020

Severity: 3-Major


Possible handshake failure with some combinations of TLS Fallback Signaling Cipher Suite Value (SCSV) and SSL profile protocol versions.


Possible handshake failure.


-- Using fallback SCSV suites. -- Using certain client SSL profile protocol versions (e.g., the virtual server is configured for TLS1.3, and the client is configured for TLS1.0 - TLS1.2).



Fix Information

The BIG-IP system now correctly handles all combinations of fallback SCSV and supported protocol versions.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips