logo

Detecting Ticketbleed (CVE-2016-9244)

ID: b1bce7e0-f53b-554c-8a61-0f28785b0ef3

STIX ID: report--b1bce7e0-f53b-554c-8a61-0f28785b0ef3

Feed Name: Fox-IT blog

Threat Score
30/100

Date Published: 2017-02-13

Date Updated: 2026-04-27

...
...

This Fox‑IT post details the Ticketbleed vulnerability (CVE-2016-9244) in F5 BIG‑IP TLS session ticket handling that can expose up to 31 bytes of uninitialized memory per session; it explains the root cause, provides mitigation advice (disable session tickets or upgrade firmware), and supplies Snort IDS rules and Wireshark filters to detect potentially vulnerable ClientHello/ServerHello exchanges.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.