CVE-2018-17539: High severity riverbed steelapp traffic manager vulnerability
The BGP daemon (bgpd) in all IP Infusion ZebOS versions to 7.10.6 and all OcNOS versions to 1.3.3.145 allow remote attackers to cause a denial of service attack via an autonomous system (AS) path containing 8 or more autonomous system number (ASN) elements.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-17539?
CVE-2018-17539 is a vulnerability in the BGP daemon (bgpd) in all IP Infusion ZebOS versions up to 7.10.6 and all OcNOS versions up to 1.3.3.145 that allows remote attackers to cause a denial of service attack.
How does CVE-2018-17539 affect F5 Big-IP Local Traffic Manager?
CVE-2018-17539 affects F5 Big-IP Local Traffic Manager versions 11.2.1 to 11.6.3, 12.1.0 to 12.1.3, 13.0.0 to 13.1.1, and 14.0.0.
What is the severity of CVE-2018-17539?
CVE-2018-17539 has a severity rating of 7.5, which is considered high.
How can I fix CVE-2018-17539?
To fix CVE-2018-17539, it is recommended to upgrade to a fixed version of IP Infusion ZebOS or OcNOS, as provided by the vendor.
Where can I find more information about CVE-2018-17539?
You can find more information about CVE-2018-17539 at the following links: [SecurityFocus](http://www.securityfocus.com/bid/106367) and [F5 Support](https://support.f5.com/csp/article/K17264695).