CVE-2018-5504

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/03/2018
Last modified:
03/10/2019

Description

In some circumstances, the Traffic Management Microkernel (TMM) does not properly handle certain malformed Websockets requests/responses, which allows remote attackers to cause a denial-of-service (DoS) or possible remote code execution on the F5 BIG-IP system running versions 13.0.0 - 13.1.0.3 or 12.1.0 - 12.1.3.1.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* 12.1.0 (including) 12.1.3.2 (excluding)
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* 13.0.0 (including) 13.1.0.4 (excluding)
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:* 12.1.0 (including) 12.1.3.2 (including)
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:* 13.0.0 (including) 13.1.0.4 (excluding)
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:* 12.1.0 (including) 12.1.3.2 (excluding)
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:* 13.0.0 (including) 13.1.0.4 (excluding)
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:* 12.1.0 (including) 12.1.3.2 (excluding)
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:* 13.0.0 (including) 13.1.0.4 (excluding)
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:* 12.1.0 (including) 12.1.3.2 (excluding)
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:* 13.0.0 (including) 13.1.0.4 (excluding)
cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:* 12.1.0 (including) 12.1.3.2 (excluding)
cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:* 13.0.0 (including) 13.1.0.4 (including)
cpe:2.3:a:f5:big-ip_edge_gateway:*:*:*:*:*:*:*:* 12.1.0 (including) 12.1.3.2 (excluding)
cpe:2.3:a:f5:big-ip_edge_gateway:*:*:*:*:*:*:*:* 13.0.0 (including) 13.1.0.4 (excluding)
cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:* 12.1.0 (including) 12.1.3.2 (excluding)