CVE-2018-5520: Medium severity F5 Big-ip Local Traffic Manager vulnerability
On an F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.1, or 11.2.1-11.6.3.1 system configured in Appliance mode, the TMOS Shell (tmsh) may allow an administrative user to use the dig utility to gain unauthorized access to file system resources.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-5520?
CVE-2018-5520 is a vulnerability that affects F5 BIG-IP systems and allows an administrative user to use the dig utility to gain unauthorized access to file system resources.
What is the severity of CVE-2018-5520?
The severity of CVE-2018-5520 is medium, with a CVSS score of 4.4.
Which software versions are affected by CVE-2018-5520?
CVE-2018-5520 affects F5 BIG-IP systems versions 11.2.1-11.6.3.1, 12.1.0-12.1.3.1, and 13.0.0-13.1.0.5 in Appliance mode.
How can an administrative user exploit CVE-2018-5520?
An administrative user can exploit CVE-2018-5520 by using the dig utility to gain unauthorized access to file system resources.
Where can I find more information about CVE-2018-5520?
You can find more information about CVE-2018-5520 on the SecurityTracker website and the F5 support website.