CVE-2018-5503: Input Validation
On F5 BIG-IP versions 13.0.0 - 13.1.0.3 or 12.0.0 - 12.1.3.1, TMM may restart when processing a specifically crafted page through a virtual server with an associated PEM policy that has content insertion as an action.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
For F5 BIG-IP virtual servers that use an associated PEM policy with content insertion as an action, ensure the virtual server/PEM policy is not exposed to requests containing specifically crafted content (e.g., restrict access at the network layer/virtual server to only trusted clients until the issue is remediated).
Event History
Frequently Asked Questions
What is the severity of CVE-2018-5503?
CVE-2018-5503 has been classified as a moderate severity vulnerability.
How do I fix CVE-2018-5503?
To remediate CVE-2018-5503, you should upgrade to F5 BIG-IP versions 12.1.3.2 or 13.1.0.4 and later.
What versions are affected by CVE-2018-5503?
CVE-2018-5503 affects F5 BIG-IP versions 13.0.0 to 13.1.0.3 and 12.0.0 to 12.1.3.1.
What is the impact of CVE-2018-5503 on systems?
The impact of CVE-2018-5503 involves a potential restart of the TMM when processing specific crafted pages.
Is exploitation of CVE-2018-5503 remote or local?
Exploitation of CVE-2018-5503 can be conducted remotely via a specially crafted page.