CVE-2018-5514: Input Validation
On F5 BIG-IP 13.1.0-13.1.0.5, maliciously crafted HTTP/2 request frames can lead to denial of service. There is data plane exposure for virtual servers when the HTTP2 profile is enabled. There is no control plane exposure to this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
F5 BIG-IPto a version that resolves this vulnerability.Fixed in 13.1.0-13.1.0.5Patch 13.1.0-13.1.0.5 - Compensating control
For affected F5 BIG-IP systems, mitigate data plane exposure by disabling the HTTP2 profile on virtual servers where it is enabled.
Event History
Frequently Asked Questions
What is CVE-2018-5514?
CVE-2018-5514 is a vulnerability in F5 BIG-IP 13.1.0-13.1.0.5 that allows a denial of service attack through maliciously crafted HTTP/2 request frames.
What is the severity of CVE-2018-5514?
The severity of CVE-2018-5514 is high with a CVSS score of 7.5.
Which products are affected by CVE-2018-5514?
F5 Big-ip Local Traffic Manager, F5 Big-ip Application Acceleration Manager, F5 BIG-IP Advanced Firewall Manager, F5 BIG-IP Analytics, F5 BIG-IP Access Policy Manager, F5 BIG-IP Application Security Manager, F5 Big-ip Edge Gateway, F5 Big-ip Global Traffic Manager, F5 Big-ip Link Controller, F5 Big-ip Policy Enforcement Manager, F5 Big-ip Webaccelerator, F5 Big-ip Websafe, and F5 Big-ip Domain Name System are affected by CVE-2018-5514.
What is the exposure for virtual servers when the HTTP2 profile is enabled?
There is data plane exposure for virtual servers when the HTTP2 profile is enabled.
Is there control plane exposure to the CVE-2018-5514 vulnerability?
No, there is no control plane exposure to the CVE-2018-5514 vulnerability.
How can I fix CVE-2018-5514?
To fix CVE-2018-5514, update F5 BIG-IP to version 13.1.0.6 or later.