CVE-2018-5538: Medium severity f5 big-ip vulnerability
On F5 BIG-IP DNS 13.1.0-13.1.0.7, 12.1.3-12.1.3.5, DNS Express / DNS Zones accept NOTIFY messages on the management interface from source IP addresses not listed in the 'Allow NOTIFY From' configuration parameter when the db variable "dnsexpress.notifyport" is set to any value other than the default of "0".
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-5538?
CVE-2018-5538 has a medium severity rating, impacting the F5 BIG-IP DNS and related modules.
How do I fix CVE-2018-5538?
To address CVE-2018-5538, update your F5 BIG-IP software to the latest version that resolves this vulnerability.
What systems are affected by CVE-2018-5538?
CVE-2018-5538 affects F5 BIG-IP DNS, Global Traffic Manager, Local Traffic Manager, and Link Controller versions specified in the vulnerability details.
What are the potential impacts of CVE-2018-5538?
Exploitation of CVE-2018-5538 may allow unauthorized NOTIFY messages to be accepted on the management interface, leading to potential misconfigurations.
Is there a workaround for CVE-2018-5538?
A temporary workaround for CVE-2018-5538 includes restricting the source IP addresses allowed to send NOTIFY messages based on your environment's requirements.