CVE-2018-5506
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
In F5 BIG-IP 13.0.0, 12.1.0-12.1.2, 11.6.1, 11.5.1-11.5.5, or 11.2.1 the Apache modules apache_auth_token_mod and mod_auth_f5_auth_token.cpp allow possible unauthenticated bruteforce on the em_server_ip authorization parameter to obtain which SSL client certificates used for mutual authentication between BIG-IQ or Enterprise Manager (EM) and managed BIG-IP devices.
Affected (65)
Products: F5: Big Ip Local Traffic Manager, Big Ip Application Acceleration Manager, Big Ip Advanced Firewall Manager, Big Ip Analytics, Big Ip Access Policy Manager, Big Ip Application Security Manager, Big Ip Edge Gateway, Big Ip Global Traffic Manager, Big Ip Link Controller, Big Ip Policy Enforcement Manager, Big Ip Webaccelerator, Big Ip Websafe, Big Ip Domain Name System
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.1 to 11.5.5 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.1 to 11.5.5 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.1 to 11.5.5 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.1 to 11.5.5 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.1 to 11.5.5 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.1 to 11.5.5 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.1 to 11.5.5 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.1 to 11.5.5 |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.1 to 11.5.5 |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.1 to 11.5.5 |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.1 to 11.5.5 |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.1 to 11.5.5 |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.1 to 11.5.5 |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.