CVE-2018-15321: Medium severity riverbed steelapp traffic manager vulnerability
When BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.0.5, 12.1.0-12.1.3.5, 11.6.0-11.6.3.2, or 11.2.1-11.5.6, BIG-IQ Centralized Management 5.0.0-5.4.0 or 4.6.0, BIG-IQ Cloud and Orchestration 1.0.0, iWorkflow 2.1.0-2.3.0, or Enterprise Manager 3.1.1 is licensed for Appliance Mode, Admin and Resource administrator roles can by-pass BIG-IP Appliance Mode restrictions to overwrite critical system files. Attackers of high privilege level are able to overwrite critical system files which bypasses security controls in place to limit TMSH commands. This is possible with an administrator or resource administrator roles when granted TMSH. Resource administrator roles must have TMSH access in order to perform this attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-15321?
CVE-2018-15321 has a medium severity rating, indicating a moderate risk of exploitation.
How do I fix CVE-2018-15321?
To fix CVE-2018-15321, apply the relevant patches or updates provided by F5 for the affected BIG-IP versions.
Which products are affected by CVE-2018-15321?
CVE-2018-15321 affects multiple versions of F5 BIG-IP and BIG-IQ products including versions 11.2.1 to 14.0.0.
What types of vulnerabilities does CVE-2018-15321 address?
CVE-2018-15321 addresses issues related to improper access control within the F5 BIG-IP and BIG-IQ management functionalities.
Is there a workaround for CVE-2018-15321?
There are no specific workarounds for CVE-2018-15321; updating to the latest patched versions is recommended to mitigate the vulnerability.