PT-2018-17021 · F5 · F5 Big-Ip

Published

2018-06-27

·

Updated

2019-10-03

·

CVE-2018-5527

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions F5 BIG-IP versions 13.1.0 through 13.1.0.7
Description A remote attacker can force the Traffic Management Microkernel (tmm) to leak memory on virtual servers configured with a Client SSL or Server SSL profile that has the SSL Forward Proxy feature enabled. This results in increased system memory usage over time, potentially causing decreased performance or a system reboot due to memory exhaustion.
Recommendations For F5 BIG-IP versions 13.1.0 through 13.1.0.7, consider disabling the SSL Forward Proxy feature as a temporary workaround to minimize the risk of memory leakage until a patch is available.

Fix

Missing Release of Resource after Effective Lifetime

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-5527

Affected Products

F5 Big-Ip