Vulnerability Name: CVE-2018-15321 (CCN-152424) Assigned: 2018-10-31 Published: 2018-10-31 Updated: 2019-10-03 Summary: When BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.0.5, 12.1.0-12.1.3.5, 11.6.0-11.6.3.2, or 11.2.1-11.5.6, BIG-IQ Centralized Management 5.0.0-5.4.0 or 4.6.0, BIG-IQ Cloud and Orchestration 1.0.0, iWorkflow 2.1.0-2.3.0, or Enterprise Manager 3.1.1 is licensed for Appliance Mode, Admin and Resource administrator roles can by-pass BIG-IP Appliance Mode restrictions to overwrite critical system files. Attackers of high privilege level are able to overwrite critical system files which bypasses security controls in place to limit TMSH commands. This is possible with an administrator or resource administrator roles when granted TMSH. Resource administrator roles must have TMSH access in order to perform this attack. CVSS v3 Severity: 4.9 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N )4.3 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): HighUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): HighAvailibility (A): None
4.4 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N )3.9 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): LocalAttack Complexity (AC): LowPrivileges Required (PR): HighUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): HighAvailibility (A): None
CVSS v2 Severity: 5.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:P )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAuthentication (Au): Single_InstanceImpact Metrics: Confidentiality (C): NoneIntegrity (I): PartialAvailibility (A): Partial
4.6 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:N/I:C/A:N )Exploitability Metrics: Access Vector (AV): LocalAccess Complexity (AC): LowAthentication (Au): Single_InstanceImpact Metrics: Confidentiality (C): NoneIntegrity (I): CompleteAvailibility (A): None
Vulnerability Type: CWE-269 Vulnerability Consequences: Bypass Security References: Source: MITRE Type: CNACVE-2018-15321 Source: XF Type: UNKNOWNf5-cve201815321-sec-bypass(152424) Source: CCN Type: F5 Security Advisory K01067037BIG-IP tmsh vulnerability CVE-2018-15321 Source: CONFIRM Type: Mitigation, Vendor Advisoryhttps://support.f5.com/csp/article/K01067037 Vulnerable Configuration: Configuration 1 :cpe:/a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:* (Version >= 11.2.1 and <= 11.5.6)OR cpe:/a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:* (Version >= 11.6.0 and <= 11.6.3.2) OR cpe:/a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:* (Version >= 12.1.0 and <= 12.1.3.5) OR cpe:/a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:* (Version >= 13.0.0 and <= 13.1.0.7) OR cpe:/a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:* (Version >= 14.0.0 and <= 14.0.0.2) Configuration 2 :cpe:/a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:* (Version >= 11.2.1 and <= 11.5.6)OR cpe:/a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:* (Version >= 11.6.0 and <= 11.6.3.2) OR cpe:/a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:* (Version >= 12.1.0 and <= 12.1.3.5) OR cpe:/a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:* (Version >= 13.0.0 and <= 13.1.0.7) OR cpe:/a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:* (Version >= 14.0.0 and <= 14.0.0.2) Configuration 3 :cpe:/a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:* (Version >= 11.2.1 and <= 11.5.6)OR cpe:/a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:* (Version >= 11.6.0 and <= 11.6.3.2) OR cpe:/a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:* (Version >= 12.1.0 and <= 12.1.3.5) OR cpe:/a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:* (Version >= 13.0.0 and <= 13.1.0.7) OR cpe:/a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:* (Version >= 14.0.0 and <= 14.0.0.2) Configuration 4 :cpe:/a:f5:big-ip_analytics:*:*:*:*:*:*:*:* (Version >= 11.2.1 and <= 11.5.6)OR cpe:/a:f5:big-ip_analytics:*:*:*:*:*:*:*:* (Version >= 11.6.0 and <= 11.6.3.2) OR cpe:/a:f5:big-ip_analytics:*:*:*:*:*:*:*:* (Version >= 12.1.0 and <= 12.1.3.5) OR cpe:/a:f5:big-ip_analytics:*:*:*:*:*:*:*:* (Version >= 13.0.0 and <= 13.1.0.7) OR cpe:/a:f5:big-ip_analytics:*:*:*:*:*:*:*:* (Version >= 14.0.0 and <= 14.0.0.2) Configuration 5 :cpe:/a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* (Version >= 11.2.1 and <= 11.5.6)OR cpe:/a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* (Version >= 11.6.0 and <= 11.6.3.2) OR cpe:/a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* (Version >= 12.1.0 and <= 12.1.3.5) OR cpe:/a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* (Version >= 13.0.0 and <= 13.1.0.7) OR cpe:/a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* (Version >= 14.0.0 and <= 14.0.0.2) Configuration 6 :cpe:/a:f5:big-ip_protocol_security_module:*:*:*:*:*:*:*:* (Version >= 11.2.1 and <= 11.5.6)OR cpe:/a:f5:big-ip_protocol_security_module:*:*:*:*:*:*:*:* (Version >= 11.6.0 and <= 11.6.3.2) OR cpe:/a:f5:big-ip_protocol_security_module:*:*:*:*:*:*:*:* (Version >= 12.1.0 and <= 12.1.3.5) OR cpe:/a:f5:big-ip_protocol_security_module:*:*:*:*:*:*:*:* (Version >= 13.0.0 and <= 13.1.0.7) OR cpe:/a:f5:big-ip_protocol_security_module:*:*:*:*:*:*:*:* (Version >= 14.0.0 and <= 14.0.0.2) Configuration 7 :cpe:/a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:* (Version >= 11.2.1 and <= 11.5.6)OR cpe:/a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:* (Version >= 11.6.0 and <= 11.6.3.2) OR cpe:/a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:* (Version >= 12.1.0 and <= 12.1.3.5) OR cpe:/a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:* (Version >= 13.0.0 and <= 13.1.0.7) OR cpe:/a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:* (Version >= 14.0.0 and <= 14.0.0.2) Configuration 8 :cpe:/a:f5:big-ip_edge_gateway:*:*:*:*:*:*:*:* (Version >= 11.2.1 and <= 11.5.6)OR cpe:/a:f5:big-ip_edge_gateway:*:*:*:*:*:*:*:* (Version >= 11.6.0 and <= 11.6.3.2) OR cpe:/a:f5:big-ip_edge_gateway:*:*:*:*:*:*:*:* (Version >= 12.1.0 and <= 12.1.3.5) OR cpe:/a:f5:big-ip_edge_gateway:*:*:*:*:*:*:*:* (Version >= 13.0.0 and <= 13.1.0.7) OR cpe:/a:f5:big-ip_edge_gateway:*:*:*:*:*:*:*:* (Version >= 14.0.0 and <= 14.0.0.2) Configuration 9 :cpe:/a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:* (Version >= 11.2.1 and <= 11.5.6)OR cpe:/a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:* (Version >= 11.6.0 and <= 11.6.3.2) OR cpe:/a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:* (Version >= 12.1.0 and <= 12.1.3.5) OR cpe:/a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:* (Version >= 13.0.0 and <= 13.1.0.7) OR cpe:/a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:* (Version >= 14.0.0 and <= 14.0.0.2) Configuration 10 :cpe:/a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:* (Version >= 11.2.1 and <= 11.5.6)OR cpe:/a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:* (Version >= 11.6.0 and <= 11.6.3.2) OR cpe:/a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:* (Version >= 12.1.0 and <= 12.1.3.5) OR cpe:/a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:* (Version >= 13.0.0 and <= 13.1.0.7) OR cpe:/a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:* (Version >= 14.0.0 and <= 14.0.0.2) Configuration 11 :cpe:/a:f5:big-ip_link_controller:*:*:*:*:*:*:*:* (Version >= 11.2.1 and <= 11.5.6)OR cpe:/a:f5:big-ip_link_controller:*:*:*:*:*:*:*:* (Version >= 11.6.0 and <= 11.6.3.2) OR cpe:/a:f5:big-ip_link_controller:*:*:*:*:*:*:*:* (Version >= 12.1.0 and <= 12.1.3.5) OR cpe:/a:f5:big-ip_link_controller:*:*:*:*:*:*:*:* (Version >= 13.0.0 and <= 13.1.0.7) OR cpe:/a:f5:big-ip_link_controller:*:*:*:*:*:*:*:* (Version >= 14.0.0 and <= 14.0.0.2) Configuration 12 :cpe:/a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:* (Version >= 11.2.1 and <= 11.5.6)OR cpe:/a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:* (Version >= 11.6.0 and <= 11.6.3.2) OR cpe:/a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:* (Version >= 12.1.0 and <= 12.1.3.5) OR cpe:/a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:* (Version >= 13.0.0 and <= 13.1.0.7) OR cpe:/a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:* (Version >= 14.0.0 and <= 14.0.0.2) Configuration 13 :cpe:/a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:* (Version >= 11.2.1 and <= 11.5.6)OR cpe:/a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:* (Version >= 11.6.0 and <= 11.6.3.2) OR cpe:/a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:* (Version >= 12.1.0 and <= 12.1.3.5) OR cpe:/a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:* (Version >= 13.0.0 and <= 13.1.0.7) OR cpe:/a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:* (Version >= 14.0.0 and <= 14.0.0.2) Configuration 14 :cpe:/a:f5:enterprise_manager:3.1.1:*:*:*:*:*:*:* Configuration 15 :cpe:/a:f5:big-iq_centralized_management:4.6.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-iq_centralized_management:*:*:*:*:*:*:*:* (Version >= 5.0.0 and <= 5.4.0) Configuration 16 :cpe:/a:f5:big-iq_cloud_and_orchestration:1.0.0:*:*:*:*:*:*:* Configuration 17 :cpe:/a:f5:iworkflow:*:*:*:*:*:*:*:* (Version >= 2.1.0 and <= 2.3.0)Configuration CCN 1 :cpe:/a:f5:enterprise_manager:3.1.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip:11.2.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip:12.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip:11.6.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip:13.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip:13.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-iq_centralized_management:5.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-iq_centralized_management:5.4.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-iq_cloud_and_orchestration:1.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-iq_centralized_management:4.6.0:*:*:*:*:*:*:* OR cpe:/a:f5:iworkflow:2.3.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip:12.1.3.7:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip:11.6.3:*:*:*:*:*:*:* OR cpe:/a:f5:iworkflow:2.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip:14.0.0:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
f5 big-ip local traffic manager *
f5 big-ip local traffic manager *
f5 big-ip local traffic manager *
f5 big-ip local traffic manager *
f5 big-ip local traffic manager *
f5 big-ip advanced firewall manager *
f5 big-ip advanced firewall manager *
f5 big-ip advanced firewall manager *
f5 big-ip advanced firewall manager *
f5 big-ip advanced firewall manager *
f5 big-ip application acceleration manager *
f5 big-ip application acceleration manager *
f5 big-ip application acceleration manager *
f5 big-ip application acceleration manager *
f5 big-ip application acceleration manager *
f5 big-ip analytics *
f5 big-ip analytics *
f5 big-ip analytics *
f5 big-ip analytics *
f5 big-ip analytics *
f5 big-ip access policy manager *
f5 big-ip access policy manager *
f5 big-ip access policy manager *
f5 big-ip access policy manager *
f5 big-ip access policy manager *
f5 big-ip protocol security module *
f5 big-ip protocol security module *
f5 big-ip protocol security module *
f5 big-ip protocol security module *
f5 big-ip protocol security module *
f5 big-ip domain name system *
f5 big-ip domain name system *
f5 big-ip domain name system *
f5 big-ip domain name system *
f5 big-ip domain name system *
f5 big-ip edge gateway *
f5 big-ip edge gateway *
f5 big-ip edge gateway *
f5 big-ip edge gateway *
f5 big-ip edge gateway *
f5 big-ip fraud protection service *
f5 big-ip fraud protection service *
f5 big-ip fraud protection service *
f5 big-ip fraud protection service *
f5 big-ip fraud protection service *
f5 big-ip global traffic manager *
f5 big-ip global traffic manager *
f5 big-ip global traffic manager *
f5 big-ip global traffic manager *
f5 big-ip global traffic manager *
f5 big-ip link controller *
f5 big-ip link controller *
f5 big-ip link controller *
f5 big-ip link controller *
f5 big-ip link controller *
f5 big-ip policy enforcement manager *
f5 big-ip policy enforcement manager *
f5 big-ip policy enforcement manager *
f5 big-ip policy enforcement manager *
f5 big-ip policy enforcement manager *
f5 big-ip webaccelerator *
f5 big-ip webaccelerator *
f5 big-ip webaccelerator *
f5 big-ip webaccelerator *
f5 big-ip webaccelerator *
f5 enterprise manager 3.1.1
f5 big-iq centralized management 4.6.0
f5 big-iq centralized management *
f5 big-iq cloud and orchestration 1.0.0
f5 iworkflow *
f5 enterprise manager 3.1.1
f5 big-ip 11.2.1
f5 big-ip 12.1.0
f5 big-ip 11.6.0
f5 big-ip 13.0.0
f5 big-ip 13.1.0
f5 big-iq centralized management 5.0.0
f5 big-iq centralized management 5.4.0
f5 big-iq cloud and orchestration 1.0.0
f5 big-iq centralized management 4.6.0
f5 iworkflow 2.3.0
f5 big-ip 12.1.3.7
f5 big-ip 11.6.3
f5 iworkflow 2.1.0
f5 big-ip 14.0.0