CVE-2018-5517: Input Validation
Published May 2, 2018
·Updated
On F5 BIG-IP 13.1.0-13.1.0.5, malformed TCP packets sent to a self IP address or a FastL4 virtual server may cause an interruption of service. The control plane is not exposed to this issue. This issue impacts the data plane virtual servers and self IPs.
Affected Software
13 affected components
F5 Big-ip Local Traffic Manager>=13.1.0<=13.1.0.5
F5 Big-ip Application Acceleration Manager>=13.1.0<=13.1.0.5
F5 BIG-IP Advanced Firewall Manager>=13.1.0<=13.1.0.5
F5 BIG-IP Analytics>=13.1.0<=13.1.0.5
F5 BIG-IP Access Policy Manager>=13.1.0<=13.1.0.5
F5 BIG-IP Application Security Manager>=13.1.0<=13.1.0.5
F5 BIG-IP Edge Gateway>=13.1.0<=13.1.0.5
F5 Big-ip Global Traffic Manager>=13.1.0<=13.1.0.5
F5 Big-ip Link Controller>=13.1.0<=13.1.0.5
F5 Big-ip Policy Enforcement Manager>=13.1.0<=13.1.0.5
F5 Big-ip Webaccelerator>=13.1.0<=13.1.0.5
F5 Big-ip Websafe>=13.1.0<=13.1.0.5
F5 Big-ip Domain Name System>=13.1.0<=13.1.0.5
Event History
May 2, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionWeakness
Data Sourced
via NVD·01:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-5517?
The severity of CVE-2018-5517 is high with a severity value of 7.5.
2
Which software versions are affected by CVE-2018-5517?
F5 BIG-IP versions 13.1.0 through 13.1.0.5 are affected by CVE-2018-5517.
3
What is the impact of CVE-2018-5517?
CVE-2018-5517 may cause an interruption of service for data plane virtual servers and self IPs on F5 BIG-IP.
4
How can I fix CVE-2018-5517?
Updating to a version beyond 13.1.0.5 will fix CVE-2018-5517 on F5 BIG-IP.
5
Where can I find more information about CVE-2018-5517?
You can find more information about CVE-2018-5517 on the following references: http://www.securitytracker.com/id/1040805, https://support.f5.com/csp/article/K25573437.