cbcvebase.
CVE-2018-5540
published 2018-07-19

CVE-2018-5540: On F5 BIG-IP 13.0.0-13.0.1, 12.1.0-12.1.3.3, 11.6.0-11.6.3.1, or 11.5.1-11.5.6, Enterprise Manager 3.1.1, BIG-IQ Centralized Management 5.0.0-5.1.0, BIG-IQ…

medium4.4CVSS 3.0
AVLACLPRHUINSUCHINAN
On F5 BIG-IP 13.0.0-13.0.1, 12.1.0-12.1.3.3, 11.6.0-11.6.3.1, or 11.5.1-11.5.6, Enterprise Manager 3.1.1, BIG-IQ Centralized Management 5.0.0-5.1.0, BIG-IQ Cloud and Orchestration 1.0.0, or F5 iWorkflow 2.1.0-2.3.0 the big3d process does not irrevocably minimize group privileges at start up.

Affected

22 ranges
VendorProductVersion rangeFixed in
f5big-ip_dns
f5big-ip_domain_name_system11.5.1 – 11.5.6
f5big-ip_domain_name_system11.6.0 – 11.6.3.1
f5big-ip_domain_name_system12.1.0 – 12.1.3.3
f5big-ip_domain_name_system13.0.0 – 13.0.1
f5big-ip_global_traffic_manager11.5.1 – 11.5.6
f5big-ip_global_traffic_manager11.6.0 – 11.6.3.1
f5big-ip_global_traffic_manager12.1.0 – 12.1.3.3
f5big-ip_global_traffic_manager13.0.0 – 13.0.1
f5big-ip_gtm
f5big-iq
f5big-iq_centralized_management5.0.0 – 5.1.0
f5big-iq_cloud_and_orchestration
f5big-iq_cloud_and_orchestration
f5enterprise_manager
f5enterprise_manager
f5f5_iworkflow
f5f5_iworkflow2.1.0 – 2.3.0
f5_networks_incbig-iq_centralized_management
f5_networks_incbig-iq_cloud_and_orchestration
f5_networks_incenterprise_manager
f5_networks_incf5_iworkflow