CVE-2018-5505: Medium severity F5 BIG-IP Analytics vulnerability
Published Mar 22, 2018
·Updated
On F5 BIG-IP versions 13.1.0 - 13.1.0.3, when ASM and AVR are both provisioned, TMM may restart while processing DNS requests when the virtual server is configured with a DNS profile and the Protocol setting is set to TCP.
Affected Software
2 affected components
F5 BIG-IP Analytics>=13.1.0<13.1.0.4
F5 BIG-IP Application Security Manager>=13.1.0<13.1.0.4
Event History
Mar 22, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionWeakness
Data Sourced
via NVD·06:29 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-5505?
CVE-2018-5505 is classified as a critical vulnerability due to potential service disruption.
2
How do I fix CVE-2018-5505?
To fix CVE-2018-5505, you should upgrade to a version of F5 BIG-IP greater than 13.1.0.3.
3
What software is affected by CVE-2018-5505?
CVE-2018-5505 affects F5 BIG-IP Analytics and F5 Application Security Manager versions 13.1.0 to 13.1.0.3.
4
What could happen if CVE-2018-5505 is exploited?
If exploited, CVE-2018-5505 may cause the TMM process to restart, leading to potential downtime.
5
Is there any workaround for CVE-2018-5505?
Currently, there are no official workarounds for CVE-2018-5505 other than updating to the latest software version.