CVE-2018-5501

Severity
5.9MEDIUM
EPSS
0.9%
top 24.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 1
Latest updateMay 14

Description

In some circumstances, on F5 BIG-IP systems running 13.0.0, 12.1.0 - 12.1.3.1, any 11.6.x or 11.5.x release, or 11.2.1, TCP DNS profile allows excessive buffering due to lack of flow control.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 2.2 | Impact: 3.6

Affected Packages13 packages

NVDf5/big-ip_link_controller11.5.111.5.4+4
NVDf5/big-ip_dns11.5.111.5.4+4
NVDf5/big-ip_websafe11.5.111.5.4+4
NVDf5/big-ip_analytics11.5.111.5.4+4
NVDf5/big-ip_edge_gateway11.5.111.5.4+4

🔴Vulnerability Details

2
GHSA
GHSA-297q-7r2m-g586: In some circumstances, on F5 BIG-IP systems running 132022-05-14
CVEList
CVE-2018-5501: In some circumstances, on F5 BIG-IP systems running 132018-03-01

💥Exploits & PoCs

1
Exploit-DB
Synaccess netBooter NP-0801DU 7.4 - Cross-Site Request Forgery (Add Admin)2018-11-21

📋Vendor Advisories

1
F5
CVE-2018-5501: In some circumstances, on F5 BIG-IP systems running 132018-03-01

💬Community

1
Bugzilla
CVE-2018-1000037 mupdf: multiple reachable assertions in the PDF parser2018-05-24
CVE-2018-5501 (MEDIUM CVSS 5.9) | In some circumstances | cvebase.io