Vulnerability Description
On an F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.1, or 11.2.1-11.6.3.1 system configured in Appliance mode, the TMOS Shell (tmsh) may allow an administrative user to use the dig utility to gain unauthorized access to file system resources.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| F5 | Big-Ip Local Traffic Manager | >= 11.2.1, <= 11.6.3 |
| F5 | Big-Ip Application Acceleration Manager | >= 11.2.1, <= 11.6.3 |
| F5 | Big-Ip Advanced Firewall Manager | >= 11.2.1, <= 11.6.3 |
| F5 | Big-Ip Analytics | >= 11.2.1, <= 11.6.3 |
| F5 | Big-Ip Access Policy Manager | >= 11.2.1, <= 11.6.3 |
| F5 | Big-Ip Application Security Manager | >= 11.2.1, <= 11.6.3 |
| F5 | Big-Ip Edge Gateway | >= 11.2.1, <= 11.6.3 |
| F5 | Big-Ip Global Traffic Manager | >= 11.2.1, <= 11.6.3 |
| F5 | Big-Ip Link Controller | >= 11.2.1, <= 11.6.3 |
| F5 | Big-Ip Policy Enforcement Manager | >= 11.2.1, <= 11.6.3 |
| F5 | Big-Ip Webaccelerator | >= 11.2.1, <= 11.6.3 |
| F5 | Big-Ip Websafe | >= 11.2.1, <= 11.6.3 |
| F5 | Big-Ip Domain Name System | >= 11.2.1, <= 11.6.3 |
Related Weaknesses (CWE)
References
- http://www.securitytracker.com/id/1040798Third Party AdvisoryVDB Entry
- https://support.f5.com/csp/article/K02043709Vendor Advisory
- http://www.securitytracker.com/id/1040798Third Party AdvisoryVDB Entry
- https://support.f5.com/csp/article/K02043709Vendor Advisory
FAQ
What is CVE-2018-5520?
CVE-2018-5520 is a vulnerability with a CVSS score of 4.4 (MEDIUM). On an F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.1, or 11.2.1-11.6.3.1 system configured in Appliance mode, the TMOS Shell (tmsh) may allow an administrative user to use the dig utility to gain unauthor...
How severe is CVE-2018-5520?
CVE-2018-5520 has been rated MEDIUM with a CVSS base score of 4.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-5520?
Check the references section above for vendor advisories and patch information. Affected products include: F5 Big-Ip Local Traffic Manager, F5 Big-Ip Application Acceleration Manager, F5 Big-Ip Advanced Firewall Manager, F5 Big-Ip Analytics, F5 Big-Ip Access Policy Manager.