Vulnerability Description
On F5 BIG-IP 13.1.0-13.1.0.3, 13.0.0, 12.1.0-12.1.3.3, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, a malformed TLS handshake causes TMM to crash leading to a disruption of service. This issue is only exposed on the data plane when Proxy SSL configuration is enabled. The control plane is not impacted by this issue.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| F5 | Big-Ip Application Acceleration Manager | >= 11.2.1, <= 11.5.5 |
| F5 | Big-Ip Local Traffic Manager | >= 11.2.1, <= 11.5.5 |
| F5 | Big-Ip Advanced Firewall Manager | >= 11.2.1, <= 11.5.5 |
| F5 | Big-Ip Analytics | >= 11.2.1, <= 11.5.5 |
| F5 | Big-Ip Access Policy Manager | >= 11.2.1, <= 11.5.5 |
| F5 | Big-Ip Application Security Manager | >= 11.2.1, <= 11.5.5 |
| F5 | Big-Ip Domain Name System | >= 11.2.1, <= 11.5.5 |
| F5 | Big-Ip Edge Gateway | >= 11.2.1, <= 11.5.5 |
| F5 | Big-Ip Global Traffic Manager | >= 11.2.1, <= 11.5.5 |
| F5 | Big-Ip Link Controller | >= 11.2.1, <= 11.5.5 |
| F5 | Big-Ip Policy Enforcement Manager | >= 11.2.1, <= 11.5.5 |
| F5 | Big-Ip Webaccelerator | >= 11.2.1, <= 11.5.5 |
| F5 | Big-Ip Websafe | >= 11.2.1, <= 11.5.5 |
Related Weaknesses (CWE)
References
- http://www.securitytracker.com/id/1041017Third Party AdvisoryVDB Entry
- https://support.f5.com/csp/article/K46940010Vendor Advisory
- http://www.securitytracker.com/id/1041017Third Party AdvisoryVDB Entry
- https://support.f5.com/csp/article/K46940010Vendor Advisory
FAQ
What is CVE-2018-5513?
CVE-2018-5513 is a vulnerability with a CVSS score of 7.5 (HIGH). On F5 BIG-IP 13.1.0-13.1.0.3, 13.0.0, 12.1.0-12.1.3.3, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, a malformed TLS handshake causes TMM to crash leading to a disruption of service. This issue is only e...
How severe is CVE-2018-5513?
CVE-2018-5513 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-5513?
Check the references section above for vendor advisories and patch information. Affected products include: F5 Big-Ip Application Acceleration Manager, F5 Big-Ip Local Traffic Manager, F5 Big-Ip Advanced Firewall Manager, F5 Big-Ip Analytics, F5 Big-Ip Access Policy Manager.