CVE-2018-5514: Input Validation

Published May 2, 2018
·
Updated

On F5 BIG-IP 13.1.0-13.1.0.5, maliciously crafted HTTP/2 request frames can lead to denial of service. There is data plane exposure for virtual servers when the HTTP2 profile is enabled. There is no control plane exposure to this issue.

Affected Software

13 affected components
F5 Big-ip Local Traffic Manager>=13.1.0<=13.1.0.5
F5 Big-ip Application Acceleration Manager>=13.1.0<=13.1.0.5
F5 BIG-IP Advanced Firewall Manager>=13.1.0<=13.1.0.5
F5 BIG-IP Analytics>=13.1.0<=13.1.0.5
F5 BIG-IP Access Policy Manager>=13.1.0<=13.1.0.5
F5 BIG-IP Application Security Manager>=13.1.0<=13.1.0.5
F5 BIG-IP Edge Gateway>=13.1.0<=13.1.0.5
F5 Big-ip Global Traffic Manager>=13.1.0<=13.1.0.5
F5 Big-ip Link Controller>=13.1.0<=13.1.0.5
F5 Big-ip Policy Enforcement Manager>=13.1.0<=13.1.0.5
F5 Big-ip Webaccelerator>=13.1.0<=13.1.0.5
F5 Big-ip Websafe>=13.1.0<=13.1.0.5
F5 Big-ip Domain Name System>=13.1.0<=13.1.0.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade F5 BIG-IP to a version that resolves this vulnerability.

    Fixed in 13.1.0-13.1.0.5Patch 13.1.0-13.1.0.5
  2. Compensating control

    For affected F5 BIG-IP systems, mitigate data plane exposure by disabling the HTTP2 profile on virtual servers where it is enabled.

Event History

May 2, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionWeakness
Data Sourced
via NVD·01:29 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is CVE-2018-5514?

CVE-2018-5514 is a vulnerability in F5 BIG-IP 13.1.0-13.1.0.5 that allows a denial of service attack through maliciously crafted HTTP/2 request frames.

2

What is the severity of CVE-2018-5514?

The severity of CVE-2018-5514 is high with a CVSS score of 7.5.

3

Which products are affected by CVE-2018-5514?

F5 Big-ip Local Traffic Manager, F5 Big-ip Application Acceleration Manager, F5 BIG-IP Advanced Firewall Manager, F5 BIG-IP Analytics, F5 BIG-IP Access Policy Manager, F5 BIG-IP Application Security Manager, F5 Big-ip Edge Gateway, F5 Big-ip Global Traffic Manager, F5 Big-ip Link Controller, F5 Big-ip Policy Enforcement Manager, F5 Big-ip Webaccelerator, F5 Big-ip Websafe, and F5 Big-ip Domain Name System are affected by CVE-2018-5514.

4

What is the exposure for virtual servers when the HTTP2 profile is enabled?

There is data plane exposure for virtual servers when the HTTP2 profile is enabled.

5

Is there control plane exposure to the CVE-2018-5514 vulnerability?

No, there is no control plane exposure to the CVE-2018-5514 vulnerability.

6

How can I fix CVE-2018-5514?

To fix CVE-2018-5514, update F5 BIG-IP to version 13.1.0.6 or later.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203