7.2

CVE-2018-5511

Exploit

On F5 BIG-IP 13.1.0-13.1.0.3 or 13.0.0, when authenticated administrative users execute commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, restrictions on allowed commands may not be enforced.

Data is provided by the National Vulnerability Database (NVD)
F5Big-ip Local Traffic Manager Version13.0.0
F5Big-ip Local Traffic Manager Version13.1.0
F5Big-ip Analytics Version13.0.0
F5Big-ip Analytics Version13.1.0
F5Big-ip Access Policy Manager Version13.0.0
F5Big-ip Access Policy Manager Version13.1.0
F5Big-ip Edge Gateway Version13.0.0
F5Big-ip Edge Gateway Version13.1.0
F5Big-ip Global Traffic Manager Version13.0.0
F5Big-ip Global Traffic Manager Version13.1.0
F5Big-ip Link Controller Version13.0.0
F5Big-ip Link Controller Version13.1.0
F5Big-ip Webaccelerator Version13.0.0
F5Big-ip Webaccelerator Version13.1.0
F5Big-ip Websafe Version13.0.0
F5Big-ip Websafe Version13.1.0
F5Big-ip Domain Name System Version13.0.0
F5Big-ip Domain Name System Version13.1.0
F5Big-ip Enterprise Manager Version3.1.1
VMwareWorkstation Version14.1.5
VMwareWorkstation Player Version15.0.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 6.04% 0.897
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.2 1.2 5.9
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
CWE-470 Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

The product uses external input with reflection to select which classes or code to use, but it does not sufficiently prevent the input from selecting improper classes or code.