PT-2018-17017 · F5 · F5 Big-Ip+1
Published
2018-06-01
·
Updated
2019-10-03
·
CVE-2018-5523
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
F5 BIG-IP versions 11.2.1, 11.5.1 through 11.5.5, 11.6.1 through 11.6.3.1, 12.1.0 through 12.1.3.1, 13.0.0, 13.1.0 through 13.1.0.3
Enterprise Manager version 3.1.1
Description
The issue affects authenticated administrative users who run commands in the Traffic Management User Interface (TMUI), also known as the BIG-IP Configuration utility. Restrictions on allowed commands may not be enforced, potentially leading to unauthorized actions.
Recommendations
For F5 BIG-IP versions 11.2.1, 11.5.1 through 11.5.5, 11.6.1 through 11.6.3.1, 12.1.0 through 12.1.3.1, 13.0.0, 13.1.0 through 13.1.0.3, consider restricting access to the TMUI to minimize the risk of exploitation.
For Enterprise Manager version 3.1.1, restrict access to the TMUI to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Enterprise Manager
F5 Big-Ip