CVE-2018-5502
On F5 BIG-IP versions 13.0.0 - 13.1.0.3, attackers may be able to disrupt services on the BIG-IP system with maliciously crafted client certificate.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.32%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
On F5 BIG-IP versions 13.0.0 - 13.1.0.3, attackers may be able to disrupt services on the BIG-IP system with maliciously crafted client certificate. This vulnerability affects virtual servers associated with Client SSL profile which enables the use of client certificate authentication. Client certificate authentication is not enabled by default in Client SSL profile. There is no control plane exposure.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 1.32% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-295
- Affected
- f5/big-ip access policy manager · f5/big-ip advanced firewall manager · f5/big-ip analytics · f5/big-ip application acceleration manager · f5/big-ip application security manager · f5/big-ip domain name system · f5/big-ip edge gateway · f5/big-ip global traffic manager · f5/big-ip link controller · f5/big-ip local traffic manager · f5/big-ip policy enforcement manager · f5/big-ip webaccelerator · f5/big-ip websafe
- Source
- f5sirt@f5.com
References
- http://www.securitytracker.com/id/1040561Third Party Advisory, VDB Entry
- https://support.f5.com/csp/article/K43121447Vendor Advisory
- http://www.securitytracker.com/id/1040561Third Party Advisory, VDB Entry
- https://support.f5.com/csp/article/K43121447Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.