CVE-2018-5548: XSS
On BIG-IP APM 11.6.0-11.6.3, an insecure AES ECB mode is used for origuri parameter in an undisclosed /vdesk link of APM virtual server configured with an access profile, allowing a malicious user to build a redirect URI value using different blocks of cipher texts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-5548?
CVE-2018-5548 is considered to have a high severity due to the potential for unauthorized access stemming from the insecure use of AES ECB mode.
How do I fix CVE-2018-5548?
To mitigate CVE-2018-5548, it is recommended to upgrade the BIG-IP APM to a version that does not use insecure encryption methods.
What versions of BIG-IP APM are affected by CVE-2018-5548?
CVE-2018-5548 affects BIG-IP APM versions 11.6.0 to 11.6.3.
What impact does CVE-2018-5548 have on my system?
CVE-2018-5548 could potentially allow an attacker to craft malicious redirect URIs enabling phishing attacks or unauthorized access.
Is there a workaround for CVE-2018-5548?
There are no specific workarounds for CVE-2018-5548 aside from upgrading to a secure version of the software.