CVE-2018-5530Uncontrolled Resource Consumption in F5 Big-ip Access Policy Manager

Severity
7.5HIGHNVD
EPSS
0.7%
top 26.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 25
Latest updateMay 14

Description

F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.5, or 11.6.0-11.6.3.1 virtual servers with HTTP/2 profiles enabled are vulnerable to "HPACK Bomb".

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages9 packages

NVDf5/big-ip_websafe11.6.011.6.3.1+2
NVDf5/big-ip_analytics11.6.011.6.3.1+2
NVDf5/big-ip_edge_gateway11.6.011.6.3.1+2
NVDf5/big-ip_access_policy_manager11.6.011.6.3.1+2
NVDf5/big-ip_local_traffic_manager11.6.011.6.3.1+2

🔴Vulnerability Details

2
GHSA
GHSA-5wcx-3ffq-75xq: F5 BIG-IP 132022-05-14
CVEList
CVE-2018-5530: F5 BIG-IP 132018-07-25

📋Vendor Advisories

1
F5
CVE-2018-5530: F5 BIG-IP 132018-07-25
CVE-2018-5530 — Uncontrolled Resource Consumption in F5 | cvebase