Vulnerability Name: | CVE-2018-5502 (CCN-140656) | ||||||||||||
Assigned: | 2018-03-22 | ||||||||||||
Published: | 2018-03-22 | ||||||||||||
Updated: | 2018-04-20 | ||||||||||||
Summary: | On F5 BIG-IP versions 13.0.0 - 13.1.0.3, attackers may be able to disrupt services on the BIG-IP system with maliciously crafted client certificate. This vulnerability affects virtual servers associated with Client SSL profile which enables the use of client certificate authentication. Client certificate authentication is not enabled by default in Client SSL profile. There is no control plane exposure. | ||||||||||||
CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) 6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
| ||||||||||||
Vulnerability Type: | CWE-295 | ||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2018-5502 Source: CCN Type: SECTRACK ID: 1040561 F5 BIG-IP Client SSL Certificate Processing Flaw Lets Remote Users Cause the Target System to Reload Source: SECTRACK Type: Third Party Advisory, VDB Entry 1040561 Source: XF Type: UNKNOWN f5-cve20185502-dos(140656) Source: CCN Type: F5 Security Advisory K43121447 BIG-IP Client SSL vulnerability CVE-2018-5502 Source: CONFIRM Type: Vendor Advisory https://support.f5.com/csp/article/K43121447 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |