CVE-2018-17539

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/12/2018
Last modified:
24/08/2020

Description

The BGP daemon (bgpd) in all IP Infusion ZebOS versions to 7.10.6 and all OcNOS versions to 1.3.3.145 allow remote attackers to cause a denial of service attack via an autonomous system (AS) path containing 8 or more autonomous system number (ASN) elements.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:* 11.2.1 (including) 11.6.3 (including)
cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:* 12.1.0 (including) 12.1.3 (including)
cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:* 13.0.0 (including) 13.1.1 (including)
cpe:2.3:a:f5:big-ip_local_traffic_manager:14.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ipinfusion:ocnos:*:*:*:*:*:*:*:* 1.3.3.145 (including)
cpe:2.3:a:ipinfusion:zebos:*:*:*:*:*:*:*:* 7.10.6 (including)