CVE-2018-5535Improper Input Validation in F5 Big-ip Fraud Protection Service

Severity
7.5HIGHNVD
EPSS
1.3%
top 20.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 19
Latest updateMay 14

Description

On F5 BIG-IP 14.0.0, 13.0.0-13.1.0, 12.1.0-12.1.3, or 11.5.1-11.6.3 specifically crafted HTTP responses, when processed by a Virtual Server with an associated QoE profile that has Video enabled, may cause TMM to incorrectly buffer response data causing the TMM to restart resulting in a Denial of Service.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages13 packages

NVDf5/big-ip_fraud_protection_service11.2.111.6.3+3
NVDf5/big-ip_analytics11.2.111.6.3+3
NVDf5/big-ip_edge_gateway11.2.111.6.3+3
NVDf5/big-ip_webaccelerator11.2.111.6.3+3
NVDf5/big-ip_link_controller11.2.111.6.3+3

🔴Vulnerability Details

2
GHSA
GHSA-cjxr-pc5w-w8vm: On F5 BIG-IP 142022-05-14
CVEList
CVE-2018-5535: On F5 BIG-IP 142018-07-19

📋Vendor Advisories

1
F5
CVE-2018-5535: On F5 BIG-IP 142018-07-19
CVE-2018-5535 — Improper Input Validation in F5 | cvebase