CVE-2018-5546
The svpn and policyserver components of the F5 BIG-IP APM client prior to version 7.1.7.1 for Linux and macOS runs as a privileged process and can allow an unprivileged user to get ownership of files owned by root on the local client host.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.45%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The svpn and policyserver components of the F5 BIG-IP APM client prior to version 7.1.7.1 for Linux and macOS runs as a privileged process and can allow an unprivileged user to get ownership of files owned by root on the local client host. A malicious local unprivileged user may gain knowledge of sensitive information, manipulate certain data, or assume super-user privileges on the local client host.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.45% probability · 38th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-732
- Affected
- f5/big-ip access policy manager client · f5/big-ip access policy manager
- Source
- f5sirt@f5.com
References
- http://www.securitytracker.com/id/1041510Broken Link
- https://github.com/mirchr/security-research/blob/master/vulnerabilities/F5/CVE-2018-5529.txtExploit, Third Party Advisory
- https://support.f5.com/csp/article/K54431371Vendor Advisory
- http://www.securitytracker.com/id/1041510Broken Link
- https://github.com/mirchr/security-research/blob/master/vulnerabilities/F5/CVE-2018-5529.txtExploit, Third Party Advisory
- https://support.f5.com/csp/article/K54431371Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.