Vulnerability Description
On F5 BIG-IP 13.1.0-13.1.0.5, maliciously crafted HTTP/2 request frames can lead to denial of service. There is data plane exposure for virtual servers when the HTTP2 profile is enabled. There is no control plane exposure to this issue.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| F5 | Big-Ip Local Traffic Manager | >= 13.1.0, <= 13.1.0.5 |
| F5 | Big-Ip Application Acceleration Manager | >= 13.1.0, <= 13.1.0.5 |
| F5 | Big-Ip Advanced Firewall Manager | >= 13.1.0, <= 13.1.0.5 |
| F5 | Big-Ip Analytics | >= 13.1.0, <= 13.1.0.5 |
| F5 | Big-Ip Access Policy Manager | >= 13.1.0, <= 13.1.0.5 |
| F5 | Big-Ip Application Security Manager | >= 13.1.0, <= 13.1.0.5 |
| F5 | Big-Ip Edge Gateway | >= 13.1.0, <= 13.1.0.5 |
| F5 | Big-Ip Global Traffic Manager | >= 13.1.0, <= 13.1.0.5 |
| F5 | Big-Ip Link Controller | >= 13.1.0, <= 13.1.0.5 |
| F5 | Big-Ip Policy Enforcement Manager | >= 13.1.0, <= 13.1.0.5 |
| F5 | Big-Ip Webaccelerator | >= 13.1.0, <= 13.1.0.5 |
| F5 | Big-Ip Websafe | >= 13.1.0, <= 13.1.0.5 |
| F5 | Big-Ip Domain Name System | >= 13.1.0, <= 13.1.0.5 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/104097Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1040804Third Party AdvisoryVDB Entry
- https://support.f5.com/csp/article/K45320419Vendor Advisory
- http://www.securityfocus.com/bid/104097Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1040804Third Party AdvisoryVDB Entry
- https://support.f5.com/csp/article/K45320419Vendor Advisory
FAQ
What is CVE-2018-5514?
CVE-2018-5514 is a vulnerability with a CVSS score of 7.5 (HIGH). On F5 BIG-IP 13.1.0-13.1.0.5, maliciously crafted HTTP/2 request frames can lead to denial of service. There is data plane exposure for virtual servers when the HTTP2 profile is enabled. There is no c...
How severe is CVE-2018-5514?
CVE-2018-5514 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-5514?
Check the references section above for vendor advisories and patch information. Affected products include: F5 Big-Ip Local Traffic Manager, F5 Big-Ip Application Acceleration Manager, F5 Big-Ip Advanced Firewall Manager, F5 Big-Ip Analytics, F5 Big-Ip Access Policy Manager.