CVE-2018-5540: Medium severity f5 big-ip vulnerability
On F5 BIG-IP 13.0.0-13.0.1, 12.1.0-12.1.3.3, 11.6.0-11.6.3.1, or 11.5.1-11.5.6, Enterprise Manager 3.1.1, BIG-IQ Centralized Management 5.0.0-5.1.0, BIG-IQ Cloud and Orchestration 1.0.0, or F5 iWorkflow 2.1.0-2.3.0 the big3d process does not irrevocably minimize group privileges at start up.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-5540?
CVE-2018-5540 is a vulnerability that affects F5 BIG-IP and other related products.
What is the severity of CVE-2018-5540?
The severity of CVE-2018-5540 is medium, with a severity value of 4.4.
Which software versions are affected by CVE-2018-5540?
The affected software versions include F5 BIG-IP 11.5.1-11.5.6, 11.6.0-11.6.3.1, 12.1.0-12.1.3.3, and 13.0.0-13.0.1, as well as other related products.
What is the impact of CVE-2018-5540?
CVE-2018-5540 allows the big3d process to start up without minimizing group privileges, potentially allowing unauthorized access or privilege escalation.
How can I fix CVE-2018-5540?
To fix CVE-2018-5540, users should update to the latest patched version of the affected software or apply the recommended security updates provided by the vendor.