V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2018-5511
CVE
HighConfirmedExploit available

On F5 BIG-IP 13.1.0-13.1.0.3 or 13.0.0, when authenticated administrative users execute commands in the Traffic Management User Interface (…

CVSS
7.2
High
EPSS
0.15
p96
Published
2018-01-01
Updated
2018-01-01
Description

On F5 BIG-IP 13.1.0-13.1.0.3 or 13.0.0, when authenticated administrative users execute commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, restrictions on allowed commands may not be enforced.

Tags · CWE
CWE-470
CAPEC-138
Affected products
Big-ip_access_policy_manager
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Timeline
2018-01-01
Published
2018-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: H
High (H)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.148 · p96
Known exploited (KEV)
No
Known exploits — Сканер-ВС
46600
exploitdb · https://www.exploit-db.com/exploits/46600
Enterprise
Affected products
ProductVendorStatus
big-ip_access_policy_manager*Tracked
big-ip_advanced_firewall_manager*Tracked
big-ip_analytics*Tracked
big-ip_application_acceleration_manager*Tracked
big-ip_application_security_manager*Tracked
big-ip_domain_name_system*Tracked
big-ip_edge_gateway*Tracked
big-ip_enterprise_manager*Tracked
big-ip_global_traffic_manager*Tracked
big-ip_link_controller*Tracked
big-ip_local_traffic_manager*Tracked
big-ip_policy_enforcement_manager*Tracked
big-ip_webaccelerator*Tracked
big-ip_websafe*Tracked
workstation*Tracked
workstation_player*Tracked
Source databases
CVE