← Back

CVE-2018-5540

nvd nist
Published: Jul 19, 2018Modified: Nov 21, 2024

JSON object

Loading...
4.4
Vector
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Exploitability: 0.8 / Impact: 3.6
Source: NVD

Description

On F5 BIG-IP 13.0.0-13.0.1, 12.1.0-12.1.3.3, 11.6.0-11.6.3.1, or 11.5.1-11.5.6, Enterprise Manager 3.1.1, BIG-IQ Centralized Management 5.0.0-5.1.0, BIG-IQ Cloud and Orchestration 1.0.0, or F5 iWorkflow 2.1.0-2.3.0 the big3d process does not irrevocably minimize group privileges at start up.

Affected (12)

6 products
Big Ip Domain Name System
Big Ip Global Traffic Manager
Enterprise Manager
Big Iq Centralized Management
Big Iq Cloud And Orchestration
F5 Iworkflow
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
F5
From 11.5.1 to 11.5.6
From 11.6.0 to 11.6.3.1
From 12.1.0 to 12.1.3.3
From 13.0.0 to 13.0.1
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
F5
From 11.5.1 to 11.5.6
From 11.6.0 to 11.6.3.1
From 12.1.0 to 12.1.3.3
From 13.0.0 to 13.0.1
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 3.1.1
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
From 5.0.0 to 5.1.0
Configuration E
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.0.0
Configuration F
1 vulnerable
Vulnerable SoftwareAffected Versions
From 2.1.0 to 2.3.0

References (8)

Source: f5sirt@f5.com
Third Party AdvisoryVDB Entry
Source: f5sirt@f5.com
Third Party AdvisoryVDB Entry
Source: f5sirt@f5.com
Third Party AdvisoryVDB Entry
Source: f5sirt@f5.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.