CVE-2018-5540
4.4
Vector
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Exploitability: 0.8 / Impact: 3.6
Source: NVD
Description
On F5 BIG-IP 13.0.0-13.0.1, 12.1.0-12.1.3.3, 11.6.0-11.6.3.1, or 11.5.1-11.5.6, Enterprise Manager 3.1.1, BIG-IQ Centralized Management 5.0.0-5.1.0, BIG-IQ Cloud and Orchestration 1.0.0, or F5 iWorkflow 2.1.0-2.3.0 the big3d process does not irrevocably minimize group privileges at start up.
Affected (12)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.1 to 11.5.6 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.1 to 11.5.6 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.1.1 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 5.0.0 to 5.1.0 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.0.0 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| From 2.1.0 to 2.3.0 |
References (8)
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.