CVE-2018-5524
published 2018-06-01CVE-2018-5524: Under certain conditions, on F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.1, or 11.6.1 HF2-11.6.3.1, virtual servers configured with Client SSL or Server SSL…
PriorityP429medium5.3CVSS 3.0
AVNACLPRNUINSUCNINAL
EPSS
1.72%
75.1th percentile
Under certain conditions, on F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.1, or 11.6.1 HF2-11.6.3.1, virtual servers configured with Client SSL or Server SSL profiles which make use of network hardware security module (HSM) functionality are exposed and impacted by this issue.
Affected
44 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip_aam | — | — |
| f5 | big-ip_access_policy_manager | 11.6.1 – 11.6.3 | — |
| f5 | big-ip_access_policy_manager | 12.1.0 – 12.1.3 | — |
| f5 | big-ip_access_policy_manager | 13.0.0 – 13.0.1 | — |
| f5 | big-ip_advanced_firewall_manager | 11.6.1 – 11.6.3 | — |
| f5 | big-ip_advanced_firewall_manager | 12.1.0 – 12.1.3 | — |
| f5 | big-ip_advanced_firewall_manager | 13.0.0 – 13.0.1 | — |
| f5 | big-ip_afm | — | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | 11.6.1 – 11.6.3 | — |
| f5 | big-ip_analytics | 12.1.0 – 12.1.3 | — |
| f5 | big-ip_analytics | 13.0.0 – 13.0.1 | — |
| f5 | big-ip_apm | — | — |
| f5 | big-ip_application_acceleration_manager | 11.6.1 – 11.6.3 | — |
| f5 | big-ip_application_acceleration_manager | 12.1.0 – 12.1.3 | — |
| f5 | big-ip_application_acceleration_manager | 13.0.0 – 13.0.1 | — |
| f5 | big-ip_application_security_manager | 11.6.1 – 11.6.3 | — |
| f5 | big-ip_application_security_manager | 12.1.0 – 12.1.3 | — |
| f5 | big-ip_application_security_manager | 13.0.0 – 13.0.1 | — |
| f5 | big-ip_asm | — | — |
| f5 | big-ip_edge_gateway | — | — |
| f5 | big-ip_edge_gateway | 11.6.1 – 11.6.3 | — |
| f5 | big-ip_edge_gateway | 12.1.0 – 12.1.3 | — |
| f5 | big-ip_edge_gateway | 13.0.0 – 13.0.1 | — |
| f5 | big-ip_fps | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r544-38gw-h4gw: Under certain conditions, on F5 BIG-IP 13
ghsa_unreviewed·2022-05-13
CVE-2018-5524 [MEDIUM] GHSA-r544-38gw-h4gw: Under certain conditions, on F5 BIG-IP 13
Under certain conditions, on F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.1, or 11.6.1 HF2-11.6.3.1, virtual servers configured with Client SSL or Server SSL profiles which make use of network hardware security module (HSM) functionality are exposed and impacted by this issue.
F5
CVE-2018-5524: Under certain conditions, on F5 BIG-IP 13
vendor_f5·2018-06-01·CVSS 5.3
CVE-2018-5524 [MEDIUM] CVE-2018-5524: Under certain conditions, on F5 BIG-IP 13
CVE-2018-5524: Under certain conditions, on F5 BIG-IP 13
Under certain conditions, on F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.1, or 11.6.1 HF2-11.6.3.1, virtual servers configured with Client SSL or Server SSL profiles which make use of network hardware security module (HSM) functionality are exposed and impacted by this issue.
Affected Products: BIG-IP AAM, BIG-IP AFM, BIG-IP APM, BIG-IP ASM, BIG-IP Analytics, BIG-IP Edge Gateway, BIG-IP FPS, BIG-IP LTM, BIG-IP Link Controller, BIG-IP PEM, BIG-IP WebAccelerator
Affected Versions: 11.6.1 - 11.6.3; 12.1.0 - 12.1.3; 13.0.0 - 13.0.1
F5 Advisory Articles: K53931245
F5 References: https://support.f5.com/csp/article/K53931245
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-06-01
Published