First published: Mon Apr 30 2018(Updated: )
On F5 BIG-IP 13.1.0-13.1.0.5, maliciously crafted HTTP/2 request frames can lead to denial of service. There is data plane exposure for virtual servers when the HTTP2 profile is enabled. There is no control plane exposure to this issue.
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
f5 big-ip local traffic manager | >=13.1.0<=13.1.0.5 | |
f5 big-ip application acceleration manager | >=13.1.0<=13.1.0.5 | |
F5 BIG-IP Advanced Firewall Manager | >=13.1.0<=13.1.0.5 | |
F5 BIG-IP Analytics | >=13.1.0<=13.1.0.5 | |
F5 BIG-IP Access Policy Manager | >=13.1.0<=13.1.0.5 | |
F5 BIG-IP Application Security Manager | >=13.1.0<=13.1.0.5 | |
f5 big-ip edge gateway | >=13.1.0<=13.1.0.5 | |
f5 big-ip global traffic manager | >=13.1.0<=13.1.0.5 | |
f5 big-ip link controller | >=13.1.0<=13.1.0.5 | |
f5 big-ip policy enforcement manager | >=13.1.0<=13.1.0.5 | |
f5 big-ip webaccelerator | >=13.1.0<=13.1.0.5 | |
F5 Big-ip Websafe | >=13.1.0<=13.1.0.5 | |
f5 big-ip domain name system | >=13.1.0<=13.1.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-5514 is a vulnerability in F5 BIG-IP 13.1.0-13.1.0.5 that allows a denial of service attack through maliciously crafted HTTP/2 request frames.
The severity of CVE-2018-5514 is high with a CVSS score of 7.5.
F5 Big-ip Local Traffic Manager, F5 Big-ip Application Acceleration Manager, F5 BIG-IP Advanced Firewall Manager, F5 BIG-IP Analytics, F5 BIG-IP Access Policy Manager, F5 BIG-IP Application Security Manager, F5 Big-ip Edge Gateway, F5 Big-ip Global Traffic Manager, F5 Big-ip Link Controller, F5 Big-ip Policy Enforcement Manager, F5 Big-ip Webaccelerator, F5 Big-ip Websafe, and F5 Big-ip Domain Name System are affected by CVE-2018-5514.
There is data plane exposure for virtual servers when the HTTP2 profile is enabled.
No, there is no control plane exposure to the CVE-2018-5514 vulnerability.
To fix CVE-2018-5514, update F5 BIG-IP to version 13.1.0.6 or later.