CVE-2018-5520
- EPSS 0.2%
- Published 02.05.2018 13:29:00
- Last modified 21.11.2024 04:08:59
On an F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.1, or 11.2.1-11.6.3.1 system configured in Appliance mode, the TMOS Shell (tmsh) may allow an administrative user to use the dig utility to gain unauthorized access to file system resources.
CVE-2017-6148
- EPSS 0.65%
- Published 13.04.2018 13:29:00
- Last modified 21.11.2024 03:29:08
Responses to SOCKS proxy requests made through F5 BIG-IP version 13.0.0, 12.0.0-12.1.3.1, 11.6.1-11.6.2, or 11.5.1-11.5.5 may cause a disruption of services provided by TMM. The data plane is impacted and exposed only when a SOCKS proxy profile is at...
CVE-2017-6155
- EPSS 0.65%
- Published 13.04.2018 13:29:00
- Last modified 21.11.2024 03:29:09
On F5 BIG-IP 13.0.0, 12.0.0-12.1.3.1, 11.6.0-11.6.2, 11.4.1-11.5.5, or 11.2.1, malformed SPDY or HTTP/2 requests may result in a disruption of service to TMM. Data plane is only exposed when a SPDY or HTTP/2 profile is attached to a virtual server. T...
CVE-2017-6156
- EPSS 0.39%
- Published 13.04.2018 13:29:00
- Last modified 21.11.2024 03:29:09
When the F5 BIG-IP 12.1.0-12.1.1, 11.6.0-11.6.1, 11.5.1-11.5.5, or 11.2.1 system is configured with a wildcard IPSec tunnel endpoint, it may allow a remote attacker to disrupt or impersonate the tunnels that have completed phase 1 IPSec negotiations....
CVE-2017-6158
- EPSS 0.61%
- Published 13.04.2018 13:29:00
- Last modified 21.11.2024 03:29:09
In F5 BIG-IP 12.0.0-12.1.2, 11.6.0-11.6.1, 11.5.1-11.5.5, or 11.2.1 there is a vulnerability in TMM related to handling of invalid IP addresses.
CVE-2018-5506
- EPSS 0.2%
- Published 13.04.2018 13:29:00
- Last modified 21.11.2024 04:08:56
In F5 BIG-IP 13.0.0, 12.1.0-12.1.2, 11.6.1, 11.5.1-11.5.5, or 11.2.1 the Apache modules apache_auth_token_mod and mod_auth_f5_auth_token.cpp allow possible unauthenticated bruteforce on the em_server_ip authorization parameter to obtain which SSL cli...
CVE-2018-5507
- EPSS 0.54%
- Published 13.04.2018 13:29:00
- Last modified 21.11.2024 04:08:56
On F5 BIG-IP versions 13.0.0, 12.1.0-12.1.3.1, 11.6.1-11.6.2, or 11.5.1-11.5.5, vCMP guests running on VIPRION 2100, 4200 and 4300 series blades cannot correctly decrypt ciphertext from established SSL sessions with small MTU.
CVE-2018-5510
- EPSS 0.65%
- Published 13.04.2018 13:29:00
- Last modified 21.11.2024 04:08:57
On F5 BIG-IP 11.5.4 HF4-11.5.5, the Traffic Management Microkernel (TMM) may restart when processing a specific sequence of packets on IPv6 virtual servers.
CVE-2018-5511
- EPSS 6.04%
- Published 13.04.2018 13:29:00
- Last modified 21.11.2024 04:08:57
On F5 BIG-IP 13.1.0-13.1.0.3 or 13.0.0, when authenticated administrative users execute commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, restrictions on allowed commands may not be enforc...
CVE-2018-5502
- EPSS 0.62%
- Published 22.03.2018 18:29:00
- Last modified 21.11.2024 04:08:55
On F5 BIG-IP versions 13.0.0 - 13.1.0.3, attackers may be able to disrupt services on the BIG-IP system with maliciously crafted client certificate. This vulnerability affects virtual servers associated with Client SSL profile which enables the use o...