PT-2018-17017 · F5 · F5 Big-Ip+1

Published

2018-06-01

·

Updated

2019-10-03

·

CVE-2018-5523

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions F5 BIG-IP versions 11.2.1, 11.5.1 through 11.5.5, 11.6.1 through 11.6.3.1, 12.1.0 through 12.1.3.1, 13.0.0, 13.1.0 through 13.1.0.3 Enterprise Manager version 3.1.1
Description The issue affects authenticated administrative users who run commands in the Traffic Management User Interface (TMUI), also known as the BIG-IP Configuration utility. Restrictions on allowed commands may not be enforced, potentially leading to unauthorized actions.
Recommendations For F5 BIG-IP versions 11.2.1, 11.5.1 through 11.5.5, 11.6.1 through 11.6.3.1, 12.1.0 through 12.1.3.1, 13.0.0, 13.1.0 through 13.1.0.3, consider restricting access to the TMUI to minimize the risk of exploitation. For Enterprise Manager version 3.1.1, restrict access to the TMUI to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2018-5523

Affected Products

Enterprise Manager
F5 Big-Ip