PT-2018-17040 · F5 · F5 Big-Ip Apm

Rich Mirch

·

Published

2018-08-17

·

Updated

2022-04-18

·

CVE-2018-5546

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions F5 BIG-IP APM client versions prior to 7.1.7.1 for Linux and macOS
Description The issue allows an unprivileged user to gain ownership of files owned by root on the local client host, potentially leading to the disclosure of sensitive information, data manipulation, or assumption of super-user privileges. This is due to the svpn and policyserver components running as a privileged process.
Recommendations For F5 BIG-IP APM client versions prior to 7.1.7.1 for Linux and macOS, update to version 7.1.7.1 or later to resolve the issue.

Exploit

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-5546

Affected Products

F5 Big-Ip Apm