CVE-2018-5504: High severity F5 BIG-IP Access Policy Manager vulnerability
Published Mar 22, 2018
·Updated
In some circumstances, the Traffic Management Microkernel (TMM) does not properly handle certain malformed Websockets requests/responses, which allows remote attackers to cause a denial-of-service (DoS) or possible remote code execution on the F5 BIG-IP system running versions 13.0.0 - 13.1.0.3 or 12.1.0 - 12.1.3.1.
Affected Software
25 affected components
F5 BIG-IP Access Policy Manager>=12.1.0<12.1.3.2
F5 BIG-IP Access Policy Manager>=13.0.0<13.1.0.4
F5 BIG-IP Advanced Firewall Manager>=12.1.0<=12.1.3.2
F5 BIG-IP Advanced Firewall Manager>=13.0.0<13.1.0.4
F5 BIG-IP Analytics>=12.1.0<12.1.3.2
F5 BIG-IP Analytics>=13.0.0<13.1.0.4
F5 Big-ip Application Acceleration Manager>=12.1.0<12.1.3.2
F5 Big-ip Application Acceleration Manager>=13.0.0<13.1.0.4
F5 BIG-IP Application Security Manager>=12.1.0<12.1.3.2
F5 BIG-IP Application Security Manager>=13.0.0<13.1.0.4
F5 Big-ip Domain Name System>=12.1.0<12.1.3.2
F5 Big-ip Domain Name System>=13.0.0<=13.1.0.4
F5 BIG-IP Edge Gateway>=12.1.0<12.1.3.2
F5 BIG-IP Edge Gateway>=13.0.0<13.1.0.4
F5 Big-ip Global Traffic Manager>=12.1.0<12.1.3.2
F5 Big-ip Global Traffic Manager>=13.0.0<13.1.0.4
F5 Big-ip Link Controller>=12.1.0<12.1.3.2
F5 Big-ip Link Controller>=13.0.0<13.1.0.4
F5 Big-ip Local Traffic Manager>=12.1.0<12.1.3.2
F5 Big-ip Local Traffic Manager>=13.0.0<13.1.0.4
F5 Big-ip Policy Enforcement Manager>=12.1.0<12.1.3.2
F5 Big-ip Policy Enforcement Manager>=13.0.0<13.1.0.4
F5 Big-ip Webaccelerator>=12.1.0<12.1.3.2
F5 Big-ip Webaccelerator>=13.0.0<13.1.0.4
F5 Big-ip Websafe=1.0.0
Event History
Mar 22, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionWeakness
Data Sourced
via NVD·06:29 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2018-5504.
2
What is the severity of CVE-2018-5504?
The severity of CVE-2018-5504 is critical with a CVSS score of 8.1.
3
Which software versions are affected by CVE-2018-5504?
Versions 13.0.0 - 13.1.0.3 of the F5 BIG-IP system are affected by CVE-2018-5504.
4
What is the impact of CVE-2018-5504?
CVE-2018-5504 can lead to a denial-of-service (DoS) or possible remote code execution on the F5 BIG-IP system.
5
Is there a fix available for CVE-2018-5504?
Yes, F5 has released patches to address the vulnerability. Please refer to the F5 support articles for the relevant patches.