vulnerability

F5 Networks: CVE-2018-5519: K46121888: ssldump vulnerability CVE-2018-5519

Severity
6
CVSS
(AV:N/AC:L/Au:S/C:N/I:P/A:P)
Published
Apr 30, 2018
Added
May 1, 2018
Modified
Aug 23, 2024

Description

On F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.3, or 11.2.1-11.6.3.1, administrative users by way of undisclosed methods can exploit the ssldump utility to write to arbitrary file paths. For users who do not have Advanced Shell access (for example, any user when licensed for Appliance Mode), this allows more permissive file access than intended.

Solution

f5-big-ip-upgrade-latest
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.