PT-2018-16996 · F5 · Big-Ip

Publicado

2018-03-22

·

Atualizado

2018-04-20

·

CVE-2018-5502

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions F5 BIG-IP versions 13.0.0 through 13.1.0.3
Description The issue allows attackers to disrupt services on the BIG-IP system using maliciously crafted client certificates. This affects virtual servers associated with the Client SSL profile, which has client certificate authentication enabled. By default, client certificate authentication is not enabled in the Client SSL profile. The control plane is not exposed.
Recommendations For F5 BIG-IP versions 13.0.0 through 13.1.0.3, consider disabling client certificate authentication in the Client SSL profile until a fix is available. Restrict access to virtual servers associated with the Client SSL profile to minimize the risk of exploitation.

Correção

Improper Certificate Validation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-5502

Produtos afetados

Big-Ip