Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-5502


On F5 BIG-IP versions 13.0.0 - 13.1.0.3, attackers may be able to disrupt services on the BIG-IP system with maliciously crafted client certificate. This vulnerability affects virtual servers associated with Client SSL profile which enables the use of client certificate authentication. Client certificate authentication is not enabled by default in Client SSL profile. There is no control plane exposure.


Published

2018-03-22T18:29:00.510

Last Modified

2024-11-21T04:08:55.943

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-295

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application f5 big-ip_access_policy_manager < 13.1.0.4 Yes
Application f5 big-ip_advanced_firewall_manager < 13.1.0.4 Yes
Application f5 big-ip_analytics < 13.1.0.4 Yes
Application f5 big-ip_application_acceleration_manager < 13.1.0.4 Yes
Application f5 big-ip_application_security_manager < 13.1.0.4 Yes
Application f5 big-ip_domain_name_system ≤ 13.1.0.4 Yes
Application f5 big-ip_edge_gateway < 13.1.0.4 Yes
Application f5 big-ip_global_traffic_manager < 13.1.0.4 Yes
Application f5 big-ip_link_controller < 13.1.0.4 Yes
Application f5 big-ip_local_traffic_manager < 13.1.0.4 Yes
Application f5 big-ip_policy_enforcement_manager < 13.1.0.4 Yes
Application f5 big-ip_webaccelerator < 13.1.0.4 Yes
Application f5 big-ip_websafe 1.0.0 Yes

References