ID

VAR-201805-0923


CVE

CVE-2018-5516


TITLE

plural F5 Access control vulnerabilities in products

Trust: 0.8

sources: JVNDB: JVNDB-2018-004934

DESCRIPTION

On F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.2, or 11.2.1-11.6.3.1, Enterprise Manager 3.1.1, BIG-IQ Centralized Management 5.0.0-5.4.0 or 4.6.0, BIG-IQ Cloud and Orchestration 1.0.0, or F5 iWorkflow 2.0.2-2.3.0, authenticated users granted TMOS Shell (tmsh) access can access objects on the file system which would normally be disallowed by tmsh restrictions. This allows for authenticated, low privileged attackers to exfiltrate objects on the file system which should not be allowed. plural F5 The product contains an access control vulnerability.Information may be obtained. F5BIG-IPLTM and other products are products of American F5 Company. F5BIG-IPLTM is a local traffic manager; BIG-IPAAM is an application acceleration manager. TMOSShell (tmsh) is one of the command line tools. There are security vulnerabilities in TMOSShell in several F5 products. An attacker could exploit this vulnerability to obtain objects on the file system. F5 BIG-IP LTM, etc. The following products and versions are affected: F5 BIG-IP LTM version 13.0.0 to 13.1.0.5, 12.1.0 to 12.1.2, 11.2.1 to 11.6.3.1; BIG-IP AAM version 13.0.0 to version 13.1.0.5, version 12.1.0 to version 12.1.2, version 11.2.1 to version 11.6.3.1; BIG-IP AFM version 13.0.0 to version 13.1.0.5, version 12.1.0 to version 12.1.2, 11.2.1 to 11.6.3.1; BIG-IP Analytics 13.0.0 to 13.1.0.5, 12.1.0 to 12.1.2, 11.2.1 to 11.6.3.1; BIG-IP APM 13.0. 0 to 13.1.0.5, 12.1.0 to 12.1.2, 11.2.1 to 11.6.3.1; BIG-IP ASM 13.0.0 to 13.1.0.5, 12.1.0 to 12.1.2 Versions, 11.2.1 to 11.6.3.1; BIG-IP DNS 13.0.0 to 13.1.0.5, 12.1.0 to 12.1.2, 11.2.1 to 11.6.3.1; BIG-IP Edge Gateway 13.0.0 to 13.1.0.5, 12.1.0 to 12.1.2, 11.2.1 to 11.6.3.1; BIG-IP GTM 13.0.0 to 13.1.0.5, 12.1.0 to Version 12.1.2, Version 11.2.1 to Version 11.6.3.1; BIG-IP Link Controller Version 13.0.0 to Version 13.1.0.5, Version 12.1.0 to Version 12.1

Trust: 2.25

sources: NVD: CVE-2018-5516 // JVNDB: JVNDB-2018-004934 // CNVD: CNVD-2018-10103 // VULHUB: VHN-135547

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2018-10103

AFFECTED PRODUCTS

vendor:f5model:big-iq centralized managementscope:eqversion:4.6.0

Trust: 1.6

vendor:f5model:big-iq cloud and orchestrationscope:eqversion:1.0.0

Trust: 1.6

vendor:f5model:big-ip webacceleratorscope:gteversion:13.0.0

Trust: 1.0

vendor:f5model:big-ip websafescope:gteversion:11.2.1

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:lteversion:12.1.2

Trust: 1.0

vendor:f5model:big-ip analyticsscope:lteversion:11.6.3

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:lteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:gteversion:13.0.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:lteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:gteversion:13.0.0

Trust: 1.0

vendor:f5model:big-iq centralized managementscope:lteversion:5.4.0

Trust: 1.0

vendor:f5model:big-ip websafescope:gteversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:gteversion:11.2.1

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:gteversion:13.0.0

Trust: 1.0

vendor:f5model:big-ip websafescope:lteversion:11.6.3

Trust: 1.0

vendor:f5model:big-ip analyticsscope:lteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:lteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:gteversion:12.1.0

Trust: 1.0

vendor:f5model:big-iq centralized managementscope:gteversion:5.0.0

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:lteversion:11.6.3

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:lteversion:12.1.2

Trust: 1.0

vendor:f5model:big-ip analyticsscope:gteversion:13.0.0

Trust: 1.0

vendor:f5model:big-ip websafescope:lteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:gteversion:11.2.1

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:gteversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:lteversion:12.1.2

Trust: 1.0

vendor:f5model:big-ip websafescope:gteversion:13.0.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:gteversion:11.2.1

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:lteversion:11.6.3

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:gteversion:13.0.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:gteversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:gteversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:lteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip enterprise managerscope:eqversion:3.1.1

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:gteversion:11.2.1

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:gteversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:lteversion:12.1.2

Trust: 1.0

vendor:f5model:big-ip application security managerscope:lteversion:12.1.2

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:gteversion:11.2.1

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:gteversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:lteversion:11.6.3

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:lteversion:11.6.3

Trust: 1.0

vendor:f5model:iworkflowscope:lteversion:2.3.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:gteversion:11.2.1

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:lteversion:12.1.2

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:lteversion:12.1.2

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:lteversion:11.6.3

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:gteversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:gteversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:gteversion:11.2.1

Trust: 1.0

vendor:f5model:big-ip application security managerscope:gteversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:lteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:gteversion:13.0.0

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:gteversion:11.2.1

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:lteversion:11.6.3

Trust: 1.0

vendor:f5model:big-ip application security managerscope:lteversion:11.6.3

Trust: 1.0

vendor:f5model:iworkflowscope:gteversion:2.0.2

Trust: 1.0

vendor:f5model:big-ip link controllerscope:gteversion:11.2.1

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:lteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:gteversion:13.0.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:lteversion:11.6.3

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:lteversion:12.1.2

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:lteversion:11.6.3

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:gteversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:lteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:gteversion:11.2.1

Trust: 1.0

vendor:f5model:big-ip link controllerscope:gteversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:lteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:gteversion:13.0.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:lteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:lteversion:12.1.2

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:lteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:gteversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:lteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:gteversion:13.0.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:lteversion:12.1.2

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:lteversion:12.1.2

Trust: 1.0

vendor:f5model:big-ip analyticsscope:gteversion:11.2.1

Trust: 1.0

vendor:f5model:big-ip application security managerscope:gteversion:13.0.0

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:lteversion:11.6.3

Trust: 1.0

vendor:f5model:big-ip link controllerscope:lteversion:11.6.3

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:gteversion:11.2.1

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:lteversion:12.1.2

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:gteversion:13.0.0

Trust: 1.0

vendor:f5model:big-ip websafescope:lteversion:12.1.2

Trust: 1.0

vendor:f5model:big-ip access policy managerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip advanced firewall managerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip analyticsscope: - version: -

Trust: 0.8

vendor:f5model:big-ip application acceleration managerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip application security managerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip domain name systemscope: - version: -

Trust: 0.8

vendor:f5model:big-ip edge gatewayscope: - version: -

Trust: 0.8

vendor:f5model:big-ip enterprise managerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip global traffic managerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip link controllerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip local traffic managerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip policy enforcement managerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip webacceleratorscope: - version: -

Trust: 0.8

vendor:f5model:big-ip websafescope: - version: -

Trust: 0.8

vendor:f5model:big-iq centralized managementscope: - version: -

Trust: 0.8

vendor:f5model:big-iq cloud and orchestrationscope: - version: -

Trust: 0.8

vendor:f5model:iworkflowscope: - version: -

Trust: 0.8

vendor:f5model:enterprise managerscope:eqversion:3.1.1

Trust: 0.6

vendor:f5model:big-ip ltmscope:gteversion:12.1.0,<=12.1.2

Trust: 0.6

vendor:f5model:big-ip aamscope:gteversion:12.1.0,<=12.1.2

Trust: 0.6

vendor:f5model:big-ip afmscope:gteversion:12.1.0,<=12.1.2

Trust: 0.6

vendor:f5model:big-ip apmscope:gteversion:12.1.0,<=12.1.2

Trust: 0.6

vendor:f5model:big-ip asmscope:gteversion:12.1.0,<=12.1.2

Trust: 0.6

vendor:f5model:big-ip link controllerscope:gteversion:12.1.0,<=12.1.2

Trust: 0.6

vendor:f5model:big-ip pemscope:gteversion:12.1.0,<=12.1.2

Trust: 0.6

vendor:f5model:big-ip websafescope:gteversion:12.1.0,<=12.1.2

Trust: 0.6

vendor:f5model:big-ip ltmscope:gteversion:13.0.0<=13.1.0.5

Trust: 0.6

vendor:f5model:big-ip aamscope:gteversion:13.0.0<=13.1.0.5

Trust: 0.6

vendor:f5model:big-ip afmscope:gteversion:13.0.0<=13.1.0.5

Trust: 0.6

vendor:f5model:big-ip analyticsscope:gteversion:13.0.0,<=13.1.0.5

Trust: 0.6

vendor:f5model:big-ip apmscope:gteversion:13.0.0<=13.1.0.5

Trust: 0.6

vendor:f5model:big-ip asmscope:gteversion:13.0.0<=13.1.0.5

Trust: 0.6

vendor:f5model:big-ip dnsscope:gteversion:13.0.0<=13.1.0.5

Trust: 0.6

vendor:f5model:big-ip edge gatewayscope:gteversion:13.0.0,<=13.1.0.5

Trust: 0.6

vendor:f5model:big-ip gtmscope:gteversion:13.0.0<=13.1.0.5

Trust: 0.6

vendor:f5model:big-ip link controllerscope:gteversion:13.0.0,<=13.1.0.5

Trust: 0.6

vendor:f5model:big-ip pemscope:gteversion:13.0.0<=13.1.0.5

Trust: 0.6

vendor:f5model:big-ip webacceleratorscope:gteversion:13.0.0,<=13.1.0.5

Trust: 0.6

vendor:f5model:big-ip ltmscope:gteversion:11.2.1<=11.6.3.1

Trust: 0.6

vendor:f5model:big-ip aamscope:gteversion:11.2.1<=11.6.3.1

Trust: 0.6

vendor:f5model:big-ip afmscope:gteversion:11.2.1<=11.6.3.1

Trust: 0.6

vendor:f5model:big-ip analyticsscope:gteversion:11.2.1<=11.6.3.1

Trust: 0.6

vendor:f5model:big-ip apmscope:gteversion:11.2.1<=11.6.3.1

Trust: 0.6

vendor:f5model:big-ip asmscope:gteversion:11.2.1<=11.6.3.1

Trust: 0.6

vendor:f5model:big-ip dnsscope:gteversion:11.2.1<=11.6.3.1

Trust: 0.6

vendor:f5model:big-ip edge gatewayscope:gteversion:11.2.1<=11.6.3.1

Trust: 0.6

vendor:f5model:big-ip gtmscope:gteversion:11.2.1<=11.6.3.1

Trust: 0.6

vendor:f5model:big-ip link controllerscope:gteversion:11.2.1,<=11.6.3.1

Trust: 0.6

vendor:f5model:big-ip pemscope:gteversion:11.2.1<=11.6.3.1

Trust: 0.6

vendor:f5model:big-ip webacceleratorscope:gteversion:11.2.1<=11.6.3.1

Trust: 0.6

vendor:f5model:big-ip websafescope:gteversion:11.2.1<=11.6.3.1

Trust: 0.6

vendor:f5model:big-iq centralized managementscope:gteversion:5.0.0,<=5.4.0

Trust: 0.6

vendor:f5model:iworkflowscope:gteversion:2.0.2<=2.3.0

Trust: 0.6

vendor:f5model:big-ip local traffic managerscope:eqversion:11.4.1

Trust: 0.6

vendor:f5model:big-ip local traffic managerscope:eqversion:11.5.4

Trust: 0.6

vendor:f5model:big-ip local traffic managerscope:eqversion:11.5.3

Trust: 0.6

vendor:f5model:big-ip local traffic managerscope:eqversion:11.5.1

Trust: 0.6

vendor:f5model:big-ip local traffic managerscope:eqversion:11.2.1

Trust: 0.6

vendor:f5model:big-ip local traffic managerscope:eqversion:11.5.5

Trust: 0.6

vendor:f5model:big-ip local traffic managerscope:eqversion:11.4.0

Trust: 0.6

vendor:f5model:big-ip local traffic managerscope:eqversion:11.5.0

Trust: 0.6

vendor:f5model:big-ip local traffic managerscope:eqversion:11.3.0

Trust: 0.6

vendor:f5model:big-ip local traffic managerscope:eqversion:11.5.2

Trust: 0.6

sources: CNVD: CNVD-2018-10103 // JVNDB: JVNDB-2018-004934 // CNNVD: CNNVD-201805-118 // NVD: CVE-2018-5516

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-5516
value: MEDIUM

Trust: 1.0

NVD: CVE-2018-5516
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2018-10103
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201805-118
value: MEDIUM

Trust: 0.6

VULHUB: VHN-135547
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2018-5516
severity: MEDIUM
baseScore: 4.7
vectorString: AV:L/AC:M/AU:N/C:C/I:N/A:N
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.4
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2018-10103
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-135547
severity: MEDIUM
baseScore: 4.7
vectorString: AV:L/AC:M/AU:N/C:C/I:N/A:N
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.4
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-5516
baseSeverity: MEDIUM
baseScore: 4.7
vectorString: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
attackVector: LOCAL
attackComplexity: HIGH
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 1.0
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2018-10103 // VULHUB: VHN-135547 // JVNDB: JVNDB-2018-004934 // CNNVD: CNNVD-201805-118 // NVD: CVE-2018-5516

PROBLEMTYPE DATA

problemtype:CWE-732

Trust: 1.1

problemtype:CWE-284

Trust: 0.9

sources: VULHUB: VHN-135547 // JVNDB: JVNDB-2018-004934 // NVD: CVE-2018-5516

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201805-118

TYPE

lack of information

Trust: 0.6

sources: CNNVD: CNNVD-201805-118

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-004934

PATCH

title:K37442533url:https://support.f5.com/csp/article/K37442533

Trust: 0.8

title:Patch of various F5 products TMOSShell information disclosure vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/129951

Trust: 0.6

title:Multiple F5 product TMOS Shell Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=79851

Trust: 0.6

sources: CNVD: CNVD-2018-10103 // JVNDB: JVNDB-2018-004934 // CNNVD: CNNVD-201805-118

EXTERNAL IDS

db:NVDid:CVE-2018-5516

Trust: 3.1

db:SECTRACKid:1040800

Trust: 2.3

db:SECTRACKid:1040799

Trust: 1.7

db:JVNDBid:JVNDB-2018-004934

Trust: 0.8

db:CNNVDid:CNNVD-201805-118

Trust: 0.7

db:CNVDid:CNVD-2018-10103

Trust: 0.6

db:VULHUBid:VHN-135547

Trust: 0.1

sources: CNVD: CNVD-2018-10103 // VULHUB: VHN-135547 // JVNDB: JVNDB-2018-004934 // CNNVD: CNNVD-201805-118 // NVD: CVE-2018-5516

REFERENCES

url:https://support.f5.com/csp/article/k37442533

Trust: 1.7

url:http://www.securitytracker.com/id/1040799

Trust: 1.7

url:http://www.securitytracker.com/id/1040800

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2018-5516

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-5516

Trust: 0.8

url:https://securitytracker.com/id/1040800

Trust: 0.6

sources: CNVD: CNVD-2018-10103 // VULHUB: VHN-135547 // JVNDB: JVNDB-2018-004934 // CNNVD: CNNVD-201805-118 // NVD: CVE-2018-5516

SOURCES

db:CNVDid:CNVD-2018-10103
db:VULHUBid:VHN-135547
db:JVNDBid:JVNDB-2018-004934
db:CNNVDid:CNNVD-201805-118
db:NVDid:CVE-2018-5516

LAST UPDATE DATE

2024-11-23T23:12:07.861000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2018-10103date:2018-05-23T00:00:00
db:VULHUBid:VHN-135547date:2019-10-03T00:00:00
db:JVNDBid:JVNDB-2018-004934date:2018-07-02T00:00:00
db:CNNVDid:CNNVD-201805-118date:2019-10-23T00:00:00
db:NVDid:CVE-2018-5516date:2024-11-21T04:08:58.470

SOURCES RELEASE DATE

db:CNVDid:CNVD-2018-10103date:2018-05-23T00:00:00
db:VULHUBid:VHN-135547date:2018-05-02T00:00:00
db:JVNDBid:JVNDB-2018-004934date:2018-07-02T00:00:00
db:CNNVDid:CNNVD-201805-118date:2018-05-03T00:00:00
db:NVDid:CVE-2018-5516date:2018-05-02T13:29:00.617