CVE Vulnerabilities

CVE-2018-5504

Published: Mar 22, 2018 | Modified: Oct 03, 2019
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

In some circumstances, the Traffic Management Microkernel (TMM) does not properly handle certain malformed Websockets requests/responses, which allows remote attackers to cause a denial-of-service (DoS) or possible remote code execution on the F5 BIG-IP system running versions 13.0.0 - 13.1.0.3 or 12.1.0 - 12.1.3.1.

Affected Software

Name Vendor Start Version End Version
Big-ip_access_policy_manager F5 12.1.0 (including) 12.1.3.2 (excluding)
Big-ip_access_policy_manager F5 13.0.0 (including) 13.1.0.4 (excluding)
Big-ip_advanced_firewall_manager F5 12.1.0 (including) 12.1.3.2 (including)
Big-ip_advanced_firewall_manager F5 13.0.0 (including) 13.1.0.4 (excluding)
Big-ip_analytics F5 12.1.0 (including) 12.1.3.2 (excluding)
Big-ip_analytics F5 13.0.0 (including) 13.1.0.4 (excluding)
Big-ip_application_acceleration_manager F5 12.1.0 (including) 12.1.3.2 (excluding)
Big-ip_application_acceleration_manager F5 13.0.0 (including) 13.1.0.4 (excluding)
Big-ip_application_security_manager F5 12.1.0 (including) 12.1.3.2 (excluding)
Big-ip_application_security_manager F5 13.0.0 (including) 13.1.0.4 (excluding)
Big-ip_domain_name_system F5 12.1.0 (including) 12.1.3.2 (excluding)
Big-ip_domain_name_system F5 13.0.0 (including) 13.1.0.4 (including)
Big-ip_edge_gateway F5 12.1.0 (including) 12.1.3.2 (excluding)
Big-ip_edge_gateway F5 13.0.0 (including) 13.1.0.4 (excluding)
Big-ip_global_traffic_manager F5 12.1.0 (including) 12.1.3.2 (excluding)
Big-ip_global_traffic_manager F5 13.0.0 (including) 13.1.0.4 (excluding)
Big-ip_link_controller F5 12.1.0 (including) 12.1.3.2 (excluding)
Big-ip_link_controller F5 13.0.0 (including) 13.1.0.4 (excluding)
Big-ip_local_traffic_manager F5 12.1.0 (including) 12.1.3.2 (excluding)
Big-ip_local_traffic_manager F5 13.0.0 (including) 13.1.0.4 (excluding)
Big-ip_policy_enforcement_manager F5 12.1.0 (including) 12.1.3.2 (excluding)
Big-ip_policy_enforcement_manager F5 13.0.0 (including) 13.1.0.4 (excluding)
Big-ip_webaccelerator F5 12.1.0 (including) 12.1.3.2 (excluding)
Big-ip_webaccelerator F5 13.0.0 (including) 13.1.0.4 (excluding)
Big-ip_websafe F5 1.0.0 (including) 1.0.0 (including)

References