CVE Vulnerabilities

CVE-2018-5504

Published: Mar 22, 2018 | Modified: Nov 21, 2024
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

In some circumstances, the Traffic Management Microkernel (TMM) does not properly handle certain malformed Websockets requests/responses, which allows remote attackers to cause a denial-of-service (DoS) or possible remote code execution on the F5 BIG-IP system running versions 13.0.0 - 13.1.0.3 or 12.1.0 - 12.1.3.1.

Affected Software

NameVendorStart VersionEnd Version
Big-ip_access_policy_managerF512.1.0 (including)12.1.3.2 (excluding)
Big-ip_access_policy_managerF513.0.0 (including)13.1.0.4 (excluding)
Big-ip_advanced_firewall_managerF512.1.0 (including)12.1.3.2 (including)
Big-ip_advanced_firewall_managerF513.0.0 (including)13.1.0.4 (excluding)
Big-ip_analyticsF512.1.0 (including)12.1.3.2 (excluding)
Big-ip_analyticsF513.0.0 (including)13.1.0.4 (excluding)
Big-ip_application_acceleration_managerF512.1.0 (including)12.1.3.2 (excluding)
Big-ip_application_acceleration_managerF513.0.0 (including)13.1.0.4 (excluding)
Big-ip_application_security_managerF512.1.0 (including)12.1.3.2 (excluding)
Big-ip_application_security_managerF513.0.0 (including)13.1.0.4 (excluding)
Big-ip_domain_name_systemF512.1.0 (including)12.1.3.2 (excluding)
Big-ip_domain_name_systemF513.0.0 (including)13.1.0.4 (including)
Big-ip_edge_gatewayF512.1.0 (including)12.1.3.2 (excluding)
Big-ip_edge_gatewayF513.0.0 (including)13.1.0.4 (excluding)
Big-ip_global_traffic_managerF512.1.0 (including)12.1.3.2 (excluding)
Big-ip_global_traffic_managerF513.0.0 (including)13.1.0.4 (excluding)
Big-ip_link_controllerF512.1.0 (including)12.1.3.2 (excluding)
Big-ip_link_controllerF513.0.0 (including)13.1.0.4 (excluding)
Big-ip_local_traffic_managerF512.1.0 (including)12.1.3.2 (excluding)
Big-ip_local_traffic_managerF513.0.0 (including)13.1.0.4 (excluding)
Big-ip_policy_enforcement_managerF512.1.0 (including)12.1.3.2 (excluding)
Big-ip_policy_enforcement_managerF513.0.0 (including)13.1.0.4 (excluding)
Big-ip_webacceleratorF512.1.0 (including)12.1.3.2 (excluding)
Big-ip_webacceleratorF513.0.0 (including)13.1.0.4 (excluding)
Big-ip_websafeF51.0.0 (including)1.0.0 (including)

References