CVE-2018-5538
published 2018-07-25CVE-2018-5538: On F5 BIG-IP DNS 13.1.0-13.1.0.7, 12.1.3-12.1.3.5, DNS Express / DNS Zones accept NOTIFY messages on the management interface from source IP addresses not…
PriorityP415low3.7CVSS 3.0
AVNACHPRNUINSUCNILAN
EPSS
0.78%
52.2th percentile
On F5 BIG-IP DNS 13.1.0-13.1.0.7, 12.1.3-12.1.3.5, DNS Express / DNS Zones accept NOTIFY messages on the management interface from source IP addresses not listed in the 'Allow NOTIFY From' configuration parameter when the db variable "dnsexpress.notifyport" is set to any value other than the default of "0".
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip_dns | — | — |
| f5 | big-ip_domain_name_system | <= 13.1.0.7 | — |
| f5 | big-ip_domain_name_system | 12.1.3 – 12.1.3.5 | — |
| f5 | big-ip_global_traffic_manager | 12.1.3 – 12.1.3.5 | — |
| f5 | big-ip_global_traffic_manager | 13.1.0 – 13.1.0.7 | — |
| f5 | big-ip_gtm | — | — |
| f5 | big-ip_link_controller | — | — |
| f5 | big-ip_link_controller | 12.1.3 – 12.1.3.5 | — |
| f5 | big-ip_link_controller | 13.1.0 – 13.1.0.7 | — |
| f5 | big-ip_local_traffic_manager | 12.1.3 – 12.1.3.5 | — |
| f5 | big-ip_local_traffic_manager | 13.1.0 – 13.1.0.7 | — |
| f5 | big-ip_ltm | — | — |
| f5_networks_inc | big-ip | — | — |
| f5_networks_inc | big-ip | — | — |
CVSS provenance
nvdv3.03.7LOWCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vjx8-8j32-57mf: On F5 BIG-IP DNS 13
ghsa_unreviewed·2022-05-13
CVE-2018-5538 [MEDIUM] GHSA-vjx8-8j32-57mf: On F5 BIG-IP DNS 13
On F5 BIG-IP DNS 13.1.0-13.1.0.7, 12.1.3-12.1.3.5, DNS Express / DNS Zones accept NOTIFY messages on the management interface from source IP addresses not listed in the 'Allow NOTIFY From' configuration parameter when the db variable "dnsexpress.notifyport" is set to any value other than the default of "0".
F5
CVE-2018-5538: On F5 BIG-IP DNS 13
vendor_f5·2018-07-25·CVSS 3.7
CVE-2018-5538 [LOW] CVE-2018-5538: On F5 BIG-IP DNS 13
CVE-2018-5538: On F5 BIG-IP DNS 13
On F5 BIG-IP DNS 13.1.0-13.1.0.7, 12.1.3-12.1.3.5, DNS Express / DNS Zones accept NOTIFY messages on the management interface from source IP addresses not listed in the 'Allow NOTIFY From' configuration parameter when the db variable "dnsexpress.notifyport" is set to any value other than the default of "0".
Affected Products: BIG-IP DNS, BIG-IP GTM, BIG-IP LTM, BIG-IP Link Controller
Affected Versions: 12.1.3 - 12.1.3.5; 13.1.0 - 13.1.0.7
F5 Advisory Articles: K45435121
F5 References: https://support.f5.com/csp/article/K45435121
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-07-25
Published