CVE-2018-5538
On F5 BIG-IP DNS 13.1.0-13.1.0.7, 12.1.3-12.1.3.5, DNS Express / DNS Zones accept NOTIFY messages on the management interface from source IP addresses not listed in the 'Allow NOTIFY From' configuration parameter when the db variable…
Does this matter?
Lower severity and a low EPSS score (0.78%). Track it; it rarely justifies an emergency change on its own.
Description
On F5 BIG-IP DNS 13.1.0-13.1.0.7, 12.1.3-12.1.3.5, DNS Express / DNS Zones accept NOTIFY messages on the management interface from source IP addresses not listed in the 'Allow NOTIFY From' configuration parameter when the db variable "dnsexpress.notifyport" is set to any value other than the default of "0".
- CVSS 3.0
- 3.7 LOWCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.78% probability · 54th percentile
- CISA KEV
- Not listed
- Affected
- f5/big-ip domain name system · f5/big-ip global traffic manager · f5/big-ip local traffic manager · f5/big-ip link controller
- Source
- f5sirt@f5.com
References
- https://support.f5.com/csp/article/K45435121Mitigation, Vendor Advisory
- https://support.f5.com/csp/article/K45435121Mitigation, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.