cbcvebase.
CVE-2018-5524
published 2018-06-01

CVE-2018-5524: Under certain conditions, on F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.1, or 11.6.1 HF2-11.6.3.1, virtual servers configured with Client SSL or Server SSL…

medium5.3CVSS 3.0
AVNACLPRNUINSUCNINAL
Under certain conditions, on F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.1, or 11.6.1 HF2-11.6.3.1, virtual servers configured with Client SSL or Server SSL profiles which make use of network hardware security module (HSM) functionality are exposed and impacted by this issue.

Affected

44 ranges· showing 25
VendorProductVersion rangeFixed in
f5big-ip_aam
f5big-ip_access_policy_manager11.6.1 – 11.6.3
f5big-ip_access_policy_manager12.1.0 – 12.1.3
f5big-ip_access_policy_manager13.0.0 – 13.0.1
f5big-ip_advanced_firewall_manager11.6.1 – 11.6.3
f5big-ip_advanced_firewall_manager12.1.0 – 12.1.3
f5big-ip_advanced_firewall_manager13.0.0 – 13.0.1
f5big-ip_afm
f5big-ip_analytics
f5big-ip_analytics11.6.1 – 11.6.3
f5big-ip_analytics12.1.0 – 12.1.3
f5big-ip_analytics13.0.0 – 13.0.1
f5big-ip_apm
f5big-ip_application_acceleration_manager11.6.1 – 11.6.3
f5big-ip_application_acceleration_manager12.1.0 – 12.1.3
f5big-ip_application_acceleration_manager13.0.0 – 13.0.1
f5big-ip_application_security_manager11.6.1 – 11.6.3
f5big-ip_application_security_manager12.1.0 – 12.1.3
f5big-ip_application_security_manager13.0.0 – 13.0.1
f5big-ip_asm
f5big-ip_edge_gateway
f5big-ip_edge_gateway11.6.1 – 11.6.3
f5big-ip_edge_gateway12.1.0 – 12.1.3
f5big-ip_edge_gateway13.0.0 – 13.0.1
f5big-ip_fps