5.9
CVE-2018-15311
- EPSS 3.53%
- Veröffentlicht 10.10.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:50:31
- Quelle f5sirt@f5.com
- Teams Watchlist Login
- Unerledigt Login
When F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.5, 11.6.0-11.6.3.2, or 11.5.1-11.5.6 is processing specially crafted TCP traffic with the Large Receive Offload (LRO) feature enabled, TMM may crash, leading to a failover event. This vulnerability is not exposed unless LRO is enabled, so most affected customers will be on 13.1.x. LRO has been available since 11.4.0 but is not enabled by default until 13.1.0.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
F5 ≫ Big-ip Local Traffic Manager Version >= 11.5.1 <= 11.5.6
F5 ≫ Big-ip Local Traffic Manager Version >= 11.6.0.0 <= 11.6.3.2
F5 ≫ Big-ip Local Traffic Manager Version >= 12.1.0.0 <= 12.1.3.5
F5 ≫ Big-ip Local Traffic Manager Version >= 13.0.0.0 <= 13.1.0.5
F5 ≫ Big-ip Application Acceleration Manager Version >= 11.5.1 <= 11.5.6
F5 ≫ Big-ip Application Acceleration Manager Version >= 11.6.0.0 <= 11.6.3.2
F5 ≫ Big-ip Application Acceleration Manager Version >= 12.1.0.0 <= 12.1.3.5
F5 ≫ Big-ip Application Acceleration Manager Version >= 13.0.0.0 <= 13.1.0.5
F5 ≫ Big-ip Advanced Firewall Manager Version >= 11.5.1 <= 11.5.6
F5 ≫ Big-ip Advanced Firewall Manager Version >= 11.6.0.0 <= 11.6.3.2
F5 ≫ Big-ip Advanced Firewall Manager Version >= 12.1.0.0 <= 12.1.3.5
F5 ≫ Big-ip Advanced Firewall Manager Version >= 13.0.0.0 <= 13.1.0.5
F5 ≫ Big-ip Analytics Version >= 11.5.1 <= 11.5.6
F5 ≫ Big-ip Analytics Version >= 11.6.0.0 <= 11.6.3.2
F5 ≫ Big-ip Analytics Version >= 12.1.0.0 <= 12.1.3.5
F5 ≫ Big-ip Analytics Version >= 13.0.0.0 <= 13.1.0.5
F5 ≫ Big-ip Access Policy Manager Version >= 11.5.1 <= 11.5.6
F5 ≫ Big-ip Access Policy Manager Version >= 11.6.0.0 <= 11.6.3.2
F5 ≫ Big-ip Access Policy Manager Version >= 12.1.0.0 <= 12.1.3.5
F5 ≫ Big-ip Access Policy Manager Version >= 13.0.0.0 <= 13.1.0.5
F5 ≫ Big-ip Application Security Manager Version >= 11.5.1 <= 11.5.6
F5 ≫ Big-ip Application Security Manager Version >= 11.6.0.0 <= 11.6.3.2
F5 ≫ Big-ip Application Security Manager Version >= 12.1.0.0 <= 12.1.3.5
F5 ≫ Big-ip Application Security Manager Version >= 13.0.0.0 <= 13.1.0.5
F5 ≫ Big-ip Domain Name System Version >= 11.5.1 <= 11.5.6
F5 ≫ Big-ip Domain Name System Version >= 11.6.0.0 <= 11.6.3.2
F5 ≫ Big-ip Domain Name System Version >= 12.1.0.0 <= 12.1.3.5
F5 ≫ Big-ip Domain Name System Version >= 13.0.0.0 <= 13.1.0.5
F5 ≫ Big-ip Edge Gateway Version >= 11.5.1 <= 11.5.6
F5 ≫ Big-ip Edge Gateway Version >= 11.6.0.0 <= 11.6.3.2
F5 ≫ Big-ip Edge Gateway Version >= 12.1.0.0 <= 12.1.3.5
F5 ≫ Big-ip Edge Gateway Version >= 13.0.0.0 <= 13.1.0.5
F5 ≫ Big-ip Fraud Protection Service Version >= 11.5.1 <= 11.5.6
F5 ≫ Big-ip Fraud Protection Service Version >= 11.6.0.0 <= 11.6.3.2
F5 ≫ Big-ip Fraud Protection Service Version >= 12.1.0.0 <= 12.1.3.5
F5 ≫ Big-ip Fraud Protection Service Version >= 13.0.0.0 <= 13.1.0.5
F5 ≫ Big-ip Global Traffic Manager Version >= 11.5.1 <= 11.5.6
F5 ≫ Big-ip Global Traffic Manager Version >= 11.6.0.0 <= 11.6.3.2
F5 ≫ Big-ip Global Traffic Manager Version >= 12.1.0.0 <= 12.1.3.5
F5 ≫ Big-ip Global Traffic Manager Version >= 13.0.0.0 <= 13.1.0.5
F5 ≫ Big-ip Link Controller Version >= 11.5.1 <= 11.5.6
F5 ≫ Big-ip Link Controller Version >= 11.6.0.0 <= 11.6.3.2
F5 ≫ Big-ip Link Controller Version >= 12.1.0.0 <= 12.1.3.5
F5 ≫ Big-ip Link Controller Version >= 13.0.0.0 <= 13.1.0.5
F5 ≫ Big-ip Policy Enforcement Manager Version >= 11.5.1 <= 11.5.6
F5 ≫ Big-ip Policy Enforcement Manager Version >= 11.6.0.0 <= 11.6.3.2
F5 ≫ Big-ip Policy Enforcement Manager Version >= 12.1.0.0 <= 12.1.3.5
F5 ≫ Big-ip Policy Enforcement Manager Version >= 13.0.0.0 <= 13.1.0.5
F5 ≫ Big-ip Webaccelerator Version >= 11.5.1 <= 11.5.6
F5 ≫ Big-ip Webaccelerator Version >= 11.6.0.0 <= 11.6.3.2
F5 ≫ Big-ip Webaccelerator Version >= 12.1.0.0 <= 12.1.3.5
F5 ≫ Big-ip Webaccelerator Version >= 13.0.0.0 <= 13.1.0.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 3.53% | 0.865 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 5.9 | 2.2 | 3.6 |
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:N/A:P
|