First published: Fri Dec 28 2018(Updated: )
The BGP daemon (bgpd) in all IP Infusion ZebOS versions to 7.10.6 and all OcNOS versions to 1.3.3.145 allow remote attackers to cause a denial of service attack via an autonomous system (AS) path containing 8 or more autonomous system number (ASN) elements.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
F5 Big-ip Local Traffic Manager | >=11.2.1<=11.6.3 | |
F5 Big-ip Local Traffic Manager | >=12.1.0<=12.1.3 | |
F5 Big-ip Local Traffic Manager | >=13.0.0<=13.1.1 | |
F5 Big-ip Local Traffic Manager | =14.0.0 | |
Ipinfusion Ocnos | <=1.3.3.145 | |
Ipinfusion Zebos | <=7.10.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-17539 is a vulnerability in the BGP daemon (bgpd) in all IP Infusion ZebOS versions up to 7.10.6 and all OcNOS versions up to 1.3.3.145 that allows remote attackers to cause a denial of service attack.
CVE-2018-17539 affects F5 Big-IP Local Traffic Manager versions 11.2.1 to 11.6.3, 12.1.0 to 12.1.3, 13.0.0 to 13.1.1, and 14.0.0.
CVE-2018-17539 has a severity rating of 7.5, which is considered high.
To fix CVE-2018-17539, it is recommended to upgrade to a fixed version of IP Infusion ZebOS or OcNOS, as provided by the vendor.
You can find more information about CVE-2018-17539 at the following links: [SecurityFocus](http://www.securityfocus.com/bid/106367) and [F5 Support](https://support.f5.com/csp/article/K17264695).