Lucene search

K
f5F5F5:K66171422
HistorySep 07, 2018 - 12:00 a.m.

K66171422 : BIG-IP APM redirect vulnerability CVE-2018-5548

2018-09-0700:00:00
my.f5.com
21

0.001 Low

EPSS

Percentile

39.6%

Security Advisory Description

An insecure AES ECB mode is used for orig_uri parameter in an undisclosed /vdesk link of APM virtual server configured with an access profile, allowing a malicious user to build a redirect URI value using different blocks of cipher texts. (CVE-2018-5548)

Impact

An attacker can forge a URL with an obfuscated (encrypted and encoded) value in an orig_uriparameter. An authenticated user with an established access session to the BIG-IP APM system may be redirected to a malicious website following the forged URL.

0.001 Low

EPSS

Percentile

39.6%

Related for F5:K66171422