CVE-2018-5516: Medium severity F5 Big-ip Local Traffic Manager vulnerability
On F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.2, or 11.2.1-11.6.3.1, Enterprise Manager 3.1.1, BIG-IQ Centralized Management 5.0.0-5.4.0 or 4.6.0, BIG-IQ Cloud and Orchestration 1.0.0, or F5 iWorkflow 2.0.2-2.3.0, authenticated users granted TMOS Shell (tmsh) access can access objects on the file system which would normally be disallowed by tmsh restrictions. This allows for authenticated, low privileged attackers to exfiltrate objects on the file system which should not be allowed.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-5516?
CVE-2018-5516 is a vulnerability that allows authenticated users with TMOS Shell (tmsh) access to access objects on the file system.
What is the severity of CVE-2018-5516?
CVE-2018-5516 has a severity rating of 4.7, which is considered medium.
Which software versions are affected by CVE-2018-5516?
CVE-2018-5516 affects F5 BIG-IP versions 13.0.0-13.1.0.5, 12.1.0-12.1.2, and 11.2.1-11.6.3.1, as well as other related software.
How can I fix CVE-2018-5516?
To fix CVE-2018-5516, you should apply the necessary patches or updates provided by F5 Networks.
Where can I find more information about CVE-2018-5516?
You can find more information about CVE-2018-5516 on the SecurityTracker website and the F5 Networks support website.