Lucene search

K
cveF5CVE-2018-5518
HistoryMay 02, 2018 - 1:29 p.m.

CVE-2018-5518

2018-05-0213:29:00
f5
web.nvd.nist.gov
29
f5 big-ip
cve-2018-5518
vcmp guest
disruption of service
vulnerability
exploit
root access

CVSS2

2.3

Attack Vector

ADJACENT_NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:A/AC:M/Au:S/C:N/I:N/A:P

CVSS3

5.4

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:A/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H

AI Score

5.2

Confidence

High

EPSS

0

Percentile

12.6%

On F5 BIG-IP 13.0.0-13.1.0.5 or 12.0.0-12.1.3.3, malicious root users with access to a VCMP guest can cause a disruption of service on adjacent VCMP guests running on the same host. Exploiting this vulnerability causes the vCMPd process on the adjacent VCMP guest to restart and produce a core file. This issue is only exploitable on a VCMP guest which is operating in “host-only” or “bridged” mode. VCMP guests which are “isolated” are not impacted by this issue and do not provide mechanism to exploit the vulnerability. Guests which are deployed in “Appliance Mode” may be impacted however the exploit is not possible from an Appliance Mode guest. To exploit this vulnerability root access on a guest system deployed as “host-only” or “bridged” mode is required.

Affected configurations

Nvd
Node
f5big-ip_local_traffic_managerRange12.0.012.1.3
OR
f5big-ip_local_traffic_managerRange13.0.013.1.0
Node
f5big-ip_application_acceleration_managerRange12.0.012.1.3
OR
f5big-ip_application_acceleration_managerRange13.0.013.1.0
Node
f5big-ip_advanced_firewall_managerRange12.0.012.1.3
OR
f5big-ip_advanced_firewall_managerRange13.0.013.1.0
Node
f5big-ip_analyticsRange12.0.012.1.3
OR
f5big-ip_analyticsRange13.0.013.1.0
Node
f5big-ip_access_policy_managerRange12.0.012.1.3
OR
f5big-ip_access_policy_managerRange13.0.013.1.0
Node
f5big-ip_application_security_managerRange12.0.012.1.3
OR
f5big-ip_application_security_managerRange13.0.013.1.0
Node
f5big-ip_edge_gatewayRange12.0.012.1.3
OR
f5big-ip_edge_gatewayRange13.0.013.1.0
Node
f5big-ip_global_traffic_managerRange12.0.012.1.3
OR
f5big-ip_global_traffic_managerRange13.0.013.1.0
Node
f5big-ip_link_controllerRange12.0.012.1.3
OR
f5big-ip_link_controllerRange13.0.013.1.0
Node
f5big-ip_policy_enforcement_managerRange12.0.012.1.3
OR
f5big-ip_policy_enforcement_managerRange13.0.013.1.0
Node
f5big-ip_webacceleratorRange12.0.012.1.3
OR
f5big-ip_webacceleratorRange13.0.013.1.0
Node
f5big-ip_websafeRange12.0.012.1.3
OR
f5big-ip_websafeRange13.0.013.1.0
Node
f5big-ip_domain_name_systemRange12.0.012.1.3
OR
f5big-ip_domain_name_systemRange13.0.013.1.0
VendorProductVersionCPE
f5big-ip_local_traffic_manager*cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*
f5big-ip_application_acceleration_manager*cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*
f5big-ip_advanced_firewall_manager*cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*
f5big-ip_analytics*cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*
f5big-ip_access_policy_manager*cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
f5big-ip_application_security_manager*cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*
f5big-ip_edge_gateway*cpe:2.3:a:f5:big-ip_edge_gateway:*:*:*:*:*:*:*:*
f5big-ip_global_traffic_manager*cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*
f5big-ip_link_controller*cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*
f5big-ip_policy_enforcement_manager*cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*
Rows per page:
1-10 of 131

CNA Affected

[
  {
    "product": "BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, WebAccelerator, WebSafe)",
    "vendor": "F5 Networks, Inc.",
    "versions": [
      {
        "status": "affected",
        "version": "13.0.0-13.1.0.5"
      },
      {
        "status": "affected",
        "version": "12.0.0-12.1.3.3"
      }
    ]
  }
]

CVSS2

2.3

Attack Vector

ADJACENT_NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:A/AC:M/Au:S/C:N/I:N/A:P

CVSS3

5.4

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:A/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H

AI Score

5.2

Confidence

High

EPSS

0

Percentile

12.6%

Related for CVE-2018-5518