CVE-2018-5524: Medium severity F5 Big-ip Application Acceleration Manager vulnerability
Under certain conditions, on F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.1, or 11.6.1 HF2-11.6.3.1, virtual servers configured with Client SSL or Server SSL profiles which make use of network hardware security module (HSM) functionality are exposed and impacted by this issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-5524?
CVE-2018-5524 is classified as a medium severity vulnerability.
How do I fix CVE-2018-5524?
To fix CVE-2018-5524, you should upgrade your F5 BIG-IP software to a version that is not affected, specifically 13.1.0.6 or later, 12.1.3.2 or later, or 11.6.3.2 or later.
What software versions are affected by CVE-2018-5524?
CVE-2018-5524 affects F5 BIG-IP versions 13.0.0-13.1.0.5, 12.1.0-12.1.3.1, and 11.6.1 HF2-11.6.3.1.
What kind of services are impacted by CVE-2018-5524?
CVE-2018-5524 impacts virtual servers configured with Client SSL or Server SSL profiles utilizing network hardware security module (HSM) functionality.
Is CVE-2018-5524 widely exploited?
As of now, there is no evidence indicating that CVE-2018-5524 is being actively exploited in the wild.