ID

VAR-201810-0897


CVE

CVE-2018-15311


TITLE

plural F5 BIG-IP Product Resource management vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2018-010864

DESCRIPTION

When F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.5, 11.6.0-11.6.3.2, or 11.5.1-11.5.6 is processing specially crafted TCP traffic with the Large Receive Offload (LRO) feature enabled, TMM may crash, leading to a failover event. This vulnerability is not exposed unless LRO is enabled, so most affected customers will be on 13.1.x. LRO has been available since 11.4.0 but is not enabled by default until 13.1.0. plural F5 BIG-IP Product Contains a resource management vulnerability.Service operation interruption (DoS) There is a possibility of being put into a state. F5 BIG-IP is an all-in-one network device integrated with network traffic management, application security management, load balancing and other functions from F5 Corporation of the United States. A security vulnerability exists in the F5 BIG-IP. When the Large Receive Offload function is enabled, an attacker can exploit this vulnerability to cause TMM to restart. The following versions are affected: F5 BIG-IP version 13.0.0 to 13.1.0.5, 12.1.0 to 12.1.3.5, 11.6.0 to 11.6.3.2, 11.5.1 to 11.5.6

Trust: 1.71

sources: NVD: CVE-2018-15311 // JVNDB: JVNDB-2018-010864 // VULHUB: VHN-125558

AFFECTED PRODUCTS

vendor:f5model:big-ip fraud protection servicescope:lteversion:12.1.3.5

Trust: 1.0

vendor:f5model:big-ip link controllerscope:lteversion:13.1.0.5

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:lteversion:13.1.0.5

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:gteversion:13.0.0.0

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:lteversion:13.1.0.5

Trust: 1.0

vendor:f5model:big-ip analyticsscope:gteversion:11.5.1

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:gteversion:12.1.0.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:lteversion:13.1.0.5

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:lteversion:11.5.6

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:gteversion:13.0.0.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:gteversion:12.1.0.0

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:lteversion:11.5.6

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:lteversion:12.1.3.5

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:lteversion:12.1.3.5

Trust: 1.0

vendor:f5model:big-ip analyticsscope:gteversion:12.1.0.0

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:gteversion:11.6.0.0

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:lteversion:11.6.3.2

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:lteversion:11.5.6

Trust: 1.0

vendor:f5model:big-ip application security managerscope:lteversion:11.5.6

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:gteversion:13.0.0.0

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:gteversion:13.0.0.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:gteversion:12.1.0.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:gteversion:13.0.0.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:lteversion:12.1.3.5

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:lteversion:11.5.6

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:lteversion:11.5.6

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:lteversion:12.1.3.5

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:gteversion:11.5.1

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:gteversion:12.1.0.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:lteversion:12.1.3.5

Trust: 1.0

vendor:f5model:big-ip application security managerscope:lteversion:12.1.3.5

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:lteversion:13.1.0.5

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:gteversion:11.6.0.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:lteversion:13.1.0.5

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:gteversion:13.0.0.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:lteversion:11.6.3.2

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:lteversion:12.1.3.5

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:lteversion:11.6.3.2

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:gteversion:11.6.0.0

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:gteversion:12.1.0.0

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:gteversion:12.1.0.0

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:lteversion:12.1.3.5

Trust: 1.0

vendor:f5model:big-ip link controllerscope:gteversion:13.0.0.0

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:lteversion:11.5.6

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:lteversion:13.1.0.5

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:lteversion:11.6.3.2

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:gteversion:11.6.0.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:gteversion:13.0.0.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:lteversion:11.6.3.2

Trust: 1.0

vendor:f5model:big-ip application security managerscope:lteversion:11.6.3.2

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:gteversion:11.6.0.0

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:gteversion:12.1.0.0

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:gteversion:11.5.1

Trust: 1.0

vendor:f5model:big-ip analyticsscope:lteversion:11.5.6

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:lteversion:12.1.3.5

Trust: 1.0

vendor:f5model:big-ip link controllerscope:gteversion:12.1.0.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:lteversion:11.5.6

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:lteversion:11.5.6

Trust: 1.0

vendor:f5model:big-ip link controllerscope:lteversion:12.1.3.5

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:lteversion:11.6.3.2

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:gteversion:11.5.1

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:lteversion:11.6.3.2

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:gteversion:11.6.0.0

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:gteversion:11.6.0.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:gteversion:12.1.0.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:gteversion:11.6.0.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:gteversion:13.0.0.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:gteversion:11.5.1

Trust: 1.0

vendor:f5model:big-ip analyticsscope:lteversion:12.1.3.5

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:gteversion:11.6.0.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:lteversion:13.1.0.5

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:lteversion:13.1.0.5

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:gteversion:11.5.1

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:lteversion:11.6.3.2

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:gteversion:11.6.0.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:lteversion:11.6.3.2

Trust: 1.0

vendor:f5model:big-ip link controllerscope:gteversion:11.6.0.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:lteversion:13.1.0.5

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:lteversion:11.6.3.2

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:gteversion:11.5.1

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:gteversion:13.0.0.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:gteversion:11.5.1

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:gteversion:11.6.0.0

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:gteversion:13.0.0.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:lteversion:13.1.0.5

Trust: 1.0

vendor:f5model:big-ip analyticsscope:lteversion:11.6.3.2

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:gteversion:11.5.1

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:lteversion:13.1.0.5

Trust: 1.0

vendor:f5model:big-ip application security managerscope:gteversion:12.1.0.0

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:lteversion:11.5.6

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:gteversion:11.5.1

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:gteversion:11.5.1

Trust: 1.0

vendor:f5model:big-ip link controllerscope:lteversion:11.5.6

Trust: 1.0

vendor:f5model:big-ip analyticsscope:gteversion:11.6.0.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:gteversion:12.1.0.0

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:lteversion:11.5.6

Trust: 1.0

vendor:f5model:big-ip link controllerscope:gteversion:11.5.1

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:gteversion:13.0.0.0

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:gteversion:12.1.0.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:gteversion:11.5.1

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:lteversion:12.1.3.5

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:lteversion:11.6.3.2

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:gteversion:13.0.0.0

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:lteversion:13.1.0.5

Trust: 1.0

vendor:f5model:big-ip access policy managerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip advanced firewall managerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip analyticsscope: - version: -

Trust: 0.8

vendor:f5model:big-ip application acceleration managerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip application security managerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip domain name systemscope: - version: -

Trust: 0.8

vendor:f5model:big-ip edge gatewayscope: - version: -

Trust: 0.8

vendor:f5model:big-ip fraud protection servicescope: - version: -

Trust: 0.8

vendor:f5model:big-ip global traffic managerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip link controllerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip local traffic managerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip policy enforcement managerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip webacceleratorscope: - version: -

Trust: 0.8

vendor:f5model:big-ip webacceleratorscope:eqversion:12.1.1

Trust: 0.6

vendor:f5model:big-ip webacceleratorscope:eqversion:13.1.0

Trust: 0.6

vendor:f5model:big-ip webacceleratorscope:eqversion:11.6.3

Trust: 0.6

vendor:f5model:big-ip webacceleratorscope:eqversion:11.6.1

Trust: 0.6

vendor:f5model:big-ip webacceleratorscope:eqversion:11.6.2

Trust: 0.6

vendor:f5model:big-ip policy enforcement managerscope:eqversion:11.6.3

Trust: 0.6

vendor:f5model:big-ip webacceleratorscope:eqversion:13.0.1

Trust: 0.6

vendor:f5model:big-ip webacceleratorscope:eqversion:12.1.2

Trust: 0.6

vendor:f5model:big-ip webacceleratorscope:eqversion:12.1.3

Trust: 0.6

vendor:f5model:big-ip webacceleratorscope:eqversion:11.5.6

Trust: 0.6

sources: JVNDB: JVNDB-2018-010864 // CNNVD: CNNVD-201810-497 // NVD: CVE-2018-15311

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-15311
value: MEDIUM

Trust: 1.0

NVD: CVE-2018-15311
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201810-497
value: MEDIUM

Trust: 0.6

VULHUB: VHN-125558
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2018-15311
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-125558
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-15311
baseSeverity: MEDIUM
baseScore: 5.9
vectorString: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 2.2
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-125558 // JVNDB: JVNDB-2018-010864 // CNNVD: CNNVD-201810-497 // NVD: CVE-2018-15311

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:CWE-399

Trust: 0.9

sources: VULHUB: VHN-125558 // JVNDB: JVNDB-2018-010864 // NVD: CVE-2018-15311

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201810-497

TYPE

resource management error

Trust: 0.6

sources: CNNVD: CNNVD-201810-497

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-010864

PATCH

title:K07550539url:https://support.f5.com/csp/article/K07550539

Trust: 0.8

title:F5 BIG-IP Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=85664

Trust: 0.6

sources: JVNDB: JVNDB-2018-010864 // CNNVD: CNNVD-201810-497

EXTERNAL IDS

db:NVDid:CVE-2018-15311

Trust: 2.5

db:JVNDBid:JVNDB-2018-010864

Trust: 0.8

db:CNNVDid:CNNVD-201810-497

Trust: 0.7

db:VULHUBid:VHN-125558

Trust: 0.1

sources: VULHUB: VHN-125558 // JVNDB: JVNDB-2018-010864 // CNNVD: CNNVD-201810-497 // NVD: CVE-2018-15311

REFERENCES

url:https://support.f5.com/csp/article/k07550539

Trust: 1.7

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-15311

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-15311

Trust: 0.8

sources: VULHUB: VHN-125558 // JVNDB: JVNDB-2018-010864 // CNNVD: CNNVD-201810-497 // NVD: CVE-2018-15311

SOURCES

db:VULHUBid:VHN-125558
db:JVNDBid:JVNDB-2018-010864
db:CNNVDid:CNNVD-201810-497
db:NVDid:CVE-2018-15311

LAST UPDATE DATE

2024-11-23T22:30:12.643000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-125558date:2019-10-03T00:00:00
db:JVNDBid:JVNDB-2018-010864date:2018-12-26T00:00:00
db:CNNVDid:CNNVD-201810-497date:2019-10-23T00:00:00
db:NVDid:CVE-2018-15311date:2024-11-21T03:50:31.993

SOURCES RELEASE DATE

db:VULHUBid:VHN-125558date:2018-10-10T00:00:00
db:JVNDBid:JVNDB-2018-010864date:2018-12-26T00:00:00
db:CNNVDid:CNNVD-201810-497date:2018-10-11T00:00:00
db:NVDid:CVE-2018-15311date:2018-10-10T14:29:00.387