CVE-2018-15320: High severity riverbed steelapp traffic manager vulnerability
On BIG-IP 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1, undisclosed traffic patterns may lead to denial of service conditions for the BIG-IP system. The configuration which exposes this condition is the BIG-IP self IP address which is part of a VLAN group and has the Port Lockdown setting configured with anything other than "allow-all".
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-15320?
CVE-2018-15320 is a vulnerability on the BIG-IP system that can lead to denial of service conditions.
What is the severity of CVE-2018-15320?
CVE-2018-15320 has a severity rating of 7.5, which is considered high.
Which systems are affected by CVE-2018-15320?
CVE-2018-15320 affects BIG-IP Local Traffic Manager, BIG-IP Advanced Firewall Manager, BIG-IP Application Acceleration Manager, BIG-IP Analytics, BIG-IP Access Policy Manager, BIG-IP Protocol Security Module, BIG-IP Domain Name System, BIG-IP Edge Gateway, BIG-IP Fraud Protection Service, BIG-IP Global Traffic Manager, BIG-IP Link Controller, BIG-IP Policy Enforcement Manager, and BIG-IP Webaccelerator.
How can I fix CVE-2018-15320?
To fix CVE-2018-15320, you should update your BIG-IP software to version 14.0.0.3 or 13.1.1.2 depending on your current version.
Where can I find more information about CVE-2018-15320?
More information about CVE-2018-15320 can be found on the F5 support website: [https://support.f5.com/csp/article/K72442354](https://support.f5.com/csp/article/K72442354).