CVE-2018-5514
published 2018-05-02CVE-2018-5514: On F5 BIG-IP 13.1.0-13.1.0.5, maliciously crafted HTTP/2 request frames can lead to denial of service. There is data plane exposure for virtual servers when…
PriorityP339high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
3.96%
89.7th percentile
On F5 BIG-IP 13.1.0-13.1.0.5, maliciously crafted HTTP/2 request frames can lead to denial of service. There is data plane exposure for virtual servers when the HTTP2 profile is enabled. There is no control plane exposure to this issue.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip_aam | — | — |
| f5 | big-ip_access_policy_manager | 13.1.0 – 13.1.0.5 | — |
| f5 | big-ip_advanced_firewall_manager | 13.1.0 – 13.1.0.5 | — |
| f5 | big-ip_afm | — | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | 13.1.0 – 13.1.0.5 | — |
| f5 | big-ip_apm | — | — |
| f5 | big-ip_application_acceleration_manager | 13.1.0 – 13.1.0.5 | — |
| f5 | big-ip_application_security_manager | 13.1.0 – 13.1.0.5 | — |
| f5 | big-ip_asm | — | — |
| f5 | big-ip_dns | — | — |
| f5 | big-ip_domain_name_system | 13.1.0 – 13.1.0.5 | — |
| f5 | big-ip_edge_gateway | — | — |
| f5 | big-ip_edge_gateway | 13.1.0 – 13.1.0.5 | — |
| f5 | big-ip_global_traffic_manager | 13.1.0 – 13.1.0.5 | — |
| f5 | big-ip_gtm | — | — |
| f5 | big-ip_link_controller | — | — |
| f5 | big-ip_link_controller | 13.1.0 – 13.1.0.5 | — |
| f5 | big-ip_local_traffic_manager | 13.1.0 – 13.1.0.5 | — |
| f5 | big-ip_ltm | — | — |
| f5 | big-ip_pem | — | — |
| f5 | big-ip_policy_enforcement_manager | 13.1.0 – 13.1.0.5 | — |
| f5 | big-ip_webaccelerator | — | — |
| f5 | big-ip_webaccelerator | 13.1.0 – 13.1.0.5 | — |
| f5 | big-ip_websafe | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mfwm-cpg4-4mww: On F5 BIG-IP 13
ghsa_unreviewed·2022-05-14
CVE-2018-5514 [HIGH] CWE-20 GHSA-mfwm-cpg4-4mww: On F5 BIG-IP 13
On F5 BIG-IP 13.1.0-13.1.0.5, maliciously crafted HTTP/2 request frames can lead to denial of service. There is data plane exposure for virtual servers when the HTTP2 profile is enabled. There is no control plane exposure to this issue.
F5
CVE-2018-5514: On F5 BIG-IP 13
vendor_f5·2018-05-02·CVSS 7.5
CVE-2018-5514 [HIGH] CWE-20 CVE-2018-5514: On F5 BIG-IP 13
CVE-2018-5514: On F5 BIG-IP 13
On F5 BIG-IP 13.1.0-13.1.0.5, maliciously crafted HTTP/2 request frames can lead to denial of service. There is data plane exposure for virtual servers when the HTTP2 profile is enabled. There is no control plane exposure to this issue.
Affected Products: BIG-IP AAM, BIG-IP AFM, BIG-IP APM, BIG-IP ASM, BIG-IP Analytics, BIG-IP DNS, BIG-IP Edge Gateway, BIG-IP GTM, BIG-IP LTM, BIG-IP Link Controller, BIG-IP PEM, BIG-IP WebAccelerator, BIG-IP WebSafe
Affected Versions: 13.1.0 - 13.1.0.5
F5 Advisory Articles: K45320419
F5 References: https://support.f5.com/csp/article/K45320419
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-05-02
Published