PT-2018-16996 · F5 · Big-Ip

Published

2018-03-22

·

Updated

2018-04-20

·

CVE-2018-5502

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions F5 BIG-IP versions 13.0.0 through 13.1.0.3
Description The issue allows attackers to disrupt services on the BIG-IP system using maliciously crafted client certificates. This affects virtual servers associated with the Client SSL profile, which has client certificate authentication enabled. By default, client certificate authentication is not enabled in the Client SSL profile. The control plane is not exposed.
Recommendations For F5 BIG-IP versions 13.0.0 through 13.1.0.3, consider disabling client certificate authentication in the Client SSL profile until a fix is available. Restrict access to virtual servers associated with the Client SSL profile to minimize the risk of exploitation.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-5502

Affected Products

Big-Ip