CVE-2018-5500: Medium severity F5 Big-ip Local Traffic Manager vulnerability
On F5 BIG-IP systems running 13.0.0, 12.1.0 - 12.1.3.1, or 11.6.1 - 11.6.2, every Multipath TCP (MCTCP) connection established leaks a small amount of memory. Virtual server using TCP profile with Multipath TCP (MCTCP) feature enabled will be affected by this issue.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-5500?
CVE-2018-5500 is a vulnerability found in F5 BIG-IP systems that leaks a small amount of memory through every Multipath TCP (MCTCP) connection established.
What software is affected by CVE-2018-5500?
F5 BIG-IP systems running versions 11.6.1 - 11.6.2, 12.1.0 - 12.1.3.1, and 13.0.0 are affected by CVE-2018-5500.
How severe is the CVE-2018-5500 vulnerability?
The severity of CVE-2018-5500 is rated as medium with a severity value of 5.9.
How do I fix CVE-2018-5500?
To fix CVE-2018-5500, users should upgrade their F5 BIG-IP systems to a version that is not affected by the vulnerability.
Where can I find more information about CVE-2018-5500?
More information about CVE-2018-5500 can be found at the following references: http://www.securityfocus.com/bid/103217 and https://support.f5.com/csp/article/K33211839