CVE-2018-5531
published 2018-07-25CVE-2018-5531: Through undisclosed methods, on F5 BIG-IP 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, 11.6.0-11.6.3.1, or 11.2.1-11.5.6, adjacent network attackers can cause a denial of…
PriorityP431high7.4CVSS 3.0
AVAACLPRNUINSCCNINAH
EPSS
0.51%
40.3th percentile
Through undisclosed methods, on F5 BIG-IP 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, 11.6.0-11.6.3.1, or 11.2.1-11.5.6, adjacent network attackers can cause a denial of service for VCMP guest and host systems. Attack must be sourced from adjacent network (layer 2).
Affected
65 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip_aam | — | — |
| f5 | big-ip_access_policy_manager | 11.2.1 – 11.5.6 | — |
| f5 | big-ip_access_policy_manager | 11.6.0 – 11.6.3.1 | — |
| f5 | big-ip_access_policy_manager | 12.1.0 – 12.1.3.5 | — |
| f5 | big-ip_access_policy_manager | 13.0.0 – 13.1.0.7 | — |
| f5 | big-ip_advanced_firewall_manager | 11.2.1 – 11.5.6 | — |
| f5 | big-ip_advanced_firewall_manager | 11.6.0 – 11.6.3.1 | — |
| f5 | big-ip_advanced_firewall_manager | 12.1.0 – 12.1.3.5 | — |
| f5 | big-ip_advanced_firewall_manager | 13.0.0 – 13.1.0.7 | — |
| f5 | big-ip_afm | — | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | 11.2.1 – 11.5.6 | — |
| f5 | big-ip_analytics | 11.6.0 – 11.6.3.1 | — |
| f5 | big-ip_analytics | 12.1.0 – 12.1.3.5 | — |
| f5 | big-ip_analytics | 13.0.0 – 13.1.0.7 | — |
| f5 | big-ip_apm | — | — |
| f5 | big-ip_application_acceleration_manager | 11.2.1 – 11.5.6 | — |
| f5 | big-ip_application_acceleration_manager | 11.6.0 – 11.6.3.1 | — |
| f5 | big-ip_application_acceleration_manager | 12.1.0 – 12.1.3.5 | — |
| f5 | big-ip_application_acceleration_manager | 13.0.0 – 13.1.0.7 | — |
| f5 | big-ip_application_security_manager | 10.1.0 – 11.5.6 | — |
| f5 | big-ip_application_security_manager | 11.6.0 – 11.6.3.1 | — |
| f5 | big-ip_application_security_manager | 12.1.0 – 12.1.3.5 | — |
| f5 | big-ip_application_security_manager | 13.0.0 – 13.1.0.7 | — |
| f5 | big-ip_asm | — | — |
CVSS provenance
nvdv3.07.4HIGHCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
nvdv2.06.1MEDIUMAV:A/AC:L/Au:N/C:N/I:N/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
F5
CVE-2018-5531: Through undisclosed methods, on F5 BIG-IP 13
vendor_f5·2018-07-25·CVSS 7.4
CVE-2018-5531 [HIGH] CWE-20 CVE-2018-5531: Through undisclosed methods, on F5 BIG-IP 13
CVE-2018-5531: Through undisclosed methods, on F5 BIG-IP 13
Through undisclosed methods, on F5 BIG-IP 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, 11.6.0-11.6.3.1, or 11.2.1-11.5.6, adjacent network attackers can cause a denial of service for VCMP guest and host systems. Attack must be sourced from adjacent network (layer 2).
Affected Products: BIG-IP AAM, BIG-IP AFM, BIG-IP APM, BIG-IP ASM, BIG-IP Analytics, BIG-IP DNS, BIG-IP Edge Gateway, BIG-IP FPS, BIG-IP GTM, BIG-IP LTM, BIG-IP Link Controller, BIG-IP PEM, BIG-IP WebAccelerator
Affected Versions: 10.1.0 - 11.5.6; 11.2.1 - 11.5.6; 11.6.0 - 11.6.3.1; 12.1.0 - 12.1.3.5; 13.0.0 - 13.1.0.7
F5 Advisory Articles: K64721111
F5 References: https://support.f5.com/csp/article/K64721111
GHSA
GHSA-7mw4-4m54-jm62: Through undisclosed methods, on F5 BIG-IP 13
ghsa_unreviewed·2022-05-14
CVE-2018-5531 [HIGH] CWE-20 GHSA-7mw4-4m54-jm62: Through undisclosed methods, on F5 BIG-IP 13
Through undisclosed methods, on F5 BIG-IP 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, 11.6.0-11.6.3.1, or 11.2.1-11.5.6, adjacent network attackers can cause a denial of service for VCMP guest and host systems. Attack must be sourced from adjacent network (layer 2).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-07-25
Published