First published: Thu Mar 22 2018(Updated: )
On F5 BIG-IP versions 13.1.0 - 13.1.0.3, when ASM and AVR are both provisioned, TMM may restart while processing DNS requests when the virtual server is configured with a DNS profile and the Protocol setting is set to TCP.
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 BIG-IP Analytics | >=13.1.0<13.1.0.4 | |
F5 Application Security Manager | >=13.1.0<13.1.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-5505 is classified as a critical vulnerability due to potential service disruption.
To fix CVE-2018-5505, you should upgrade to a version of F5 BIG-IP greater than 13.1.0.3.
CVE-2018-5505 affects F5 BIG-IP Analytics and F5 Application Security Manager versions 13.1.0 to 13.1.0.3.
If exploited, CVE-2018-5505 may cause the TMM process to restart, leading to potential downtime.
Currently, there are no official workarounds for CVE-2018-5505 other than updating to the latest software version.