CVE-2018-15321

Severity
4.9MEDIUM
EPSS
0.2%
top 59.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 31
Latest updateMay 13

Description

When BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.0.5, 12.1.0-12.1.3.5, 11.6.0-11.6.3.2, or 11.2.1-11.5.6, BIG-IQ Centralized Management 5.0.0-5.4.0 or 4.6.0, BIG-IQ Cloud and Orchestration 1.0.0, iWorkflow 2.1.0-2.3.0, or Enterprise Manager 3.1.1 is licensed for Appliance Mode, Admin and Resource administrator roles can by-pass BIG-IP Appliance Mode restrictions to overwrite critical system files. Attackers of high privilege level are able to overwrite critical system files which bypasses security contr

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:NExploitability: 1.2 | Impact: 3.6

Affected Packages17 packages

🔴Vulnerability Details

2
GHSA
GHSA-h4wp-5c5q-58qf: When BIG-IP 142022-05-13
CVEList
CVE-2018-15321: When BIG-IP 142018-10-31

📋Vendor Advisories

1
F5
CVE-2018-15321: When BIG-IP 142018-10-31
CVE-2018-15321 (MEDIUM CVSS 4.9) | When BIG-IP 14.0.0-14.0.0.2 | cvebase.io