CVE-2018-15321
Attackers of high privilege level are able to overwrite critical system files which bypasses security controls in place to limit TMSH commands.
Does this matter?
Lower severity and a low EPSS score (0.90%). Track it; it rarely justifies an emergency change on its own.
Description
When BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.0.5, 12.1.0-12.1.3.5, 11.6.0-11.6.3.2, or 11.2.1-11.5.6, BIG-IQ Centralized Management 5.0.0-5.4.0 or 4.6.0, BIG-IQ Cloud and Orchestration 1.0.0, iWorkflow 2.1.0-2.3.0, or Enterprise Manager 3.1.1 is licensed for Appliance Mode, Admin and Resource administrator roles can by-pass BIG-IP Appliance Mode restrictions to overwrite critical system files. Attackers of high privilege level are able to overwrite critical system files which bypasses security controls in place to limit TMSH commands. This is possible with an administrator or resource administrator roles when granted TMSH. Resource administrator roles must have TMSH access in order to perform this attack.
- CVSS 3.0
- 4.9 MEDIUMCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.90% probability · 58th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-269
- Affected
- f5/big-ip local traffic manager · f5/big-ip advanced firewall manager · f5/big-ip application acceleration manager · f5/big-ip analytics · f5/big-ip access policy manager · f5/big-ip protocol security module · f5/big-ip domain name system · f5/big-ip edge gateway · f5/big-ip fraud protection service · f5/big-ip global traffic manager · f5/big-ip link controller · f5/big-ip policy enforcement manager · f5/big-ip webaccelerator · f5/enterprise manager · f5/big-iq centralized management · f5/big-iq cloud and orchestration · f5/iworkflow
- Source
- f5sirt@f5.com
References
- https://support.f5.com/csp/article/K01067037Mitigation, Vendor Advisory
- https://support.f5.com/csp/article/K01067037Mitigation, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.