5.3

CVE-2018-5524

Under certain conditions, on F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.1, or 11.6.1 HF2-11.6.3.1, virtual servers configured with Client SSL or Server SSL profiles which make use of network hardware security module (HSM) functionality are exposed and impacted by this issue.

Data is provided by the National Vulnerability Database (NVD)
F5Big-ip Application Acceleration Manager Version >= 11.6.1 <= 11.6.3
F5Big-ip Application Acceleration Manager Version >= 12.1.0 <= 12.1.3
F5Big-ip Application Acceleration Manager Version >= 13.0.0 <= 13.0.1
F5Big-ip Local Traffic Manager Version >= 11.6.1 <= 11.6.3
F5Big-ip Local Traffic Manager Version >= 12.1.0 <= 12.1.3
F5Big-ip Local Traffic Manager Version >= 13.0.0 <= 13.0.1
F5Big-ip Advanced Firewall Manager Version >= 11.6.1 <= 11.6.3
F5Big-ip Advanced Firewall Manager Version >= 12.1.0 <= 12.1.3
F5Big-ip Advanced Firewall Manager Version >= 13.0.0 <= 13.0.1
F5Big-ip Analytics Version >= 11.6.1 <= 11.6.3
F5Big-ip Analytics Version >= 12.1.0 <= 12.1.3
F5Big-ip Analytics Version >= 13.0.0 <= 13.0.1
F5Big-ip Access Policy Manager Version >= 11.6.1 <= 11.6.3
F5Big-ip Access Policy Manager Version >= 12.1.0 <= 12.1.3
F5Big-ip Access Policy Manager Version >= 13.0.0 <= 13.0.1
F5Big-ip Application Security Manager Version >= 11.6.1 <= 11.6.3
F5Big-ip Application Security Manager Version >= 12.1.0 <= 12.1.3
F5Big-ip Application Security Manager Version >= 13.0.0 <= 13.0.1
F5Big-ip Edge Gateway Version >= 11.6.1 <= 11.6.3
F5Big-ip Edge Gateway Version >= 12.1.0 <= 12.1.3
F5Big-ip Edge Gateway Version >= 13.0.0 <= 13.0.1
F5Big-ip Link Controller Version >= 11.6.1 <= 11.6.3
F5Big-ip Link Controller Version >= 12.1.0 <= 12.1.3
F5Big-ip Link Controller Version >= 13.0.0 <= 13.0.1
F5Big-ip Policy Enforcement Manager Version >= 11.6.1 <= 11.6.3
F5Big-ip Policy Enforcement Manager Version >= 12.1.0 <= 12.1.3
F5Big-ip Policy Enforcement Manager Version >= 13.0.0 <= 13.0.1
F5Big-ip Webaccelerator Version >= 11.6.1 <= 11.6.3
F5Big-ip Webaccelerator Version >= 12.1.0 <= 12.1.3
F5Big-ip Webaccelerator Version >= 13.0.0 <= 13.0.1
F5Big-ip Fraud Protection Service Version >= 11.6.1 <= 11.6.3
F5Big-ip Fraud Protection Service Version >= 12.1.0 <= 12.1.3
F5Big-ip Fraud Protection Service Version >= 13.0.0 <= 13.0.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.6% 0.67
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P