A local file vulnerability exists in the F5 BIG-IP Configuration utility on versions 13.0.0, 12.1.0-12.1.2, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1 that exposes files containing F5-provided data only and do not include any configuration data, proxied traffic, or other potentially sensitive customer data.
No CVSS v3.1
Attack Vector Network
Attack Complexity Low
Privileges Required Low
Scope Unchanged
Confidentiality Impact Low
Integrity Impact None
Availability Impact None
User Interaction None
Access Vector Network
Access Complexity Low
Authentication Single
Confidentiality Impact Partial
Integrity Impact None
Availability Impact None
AV:N/AC:L/Au:S/C:P/I:N/A:N
Vendors | Products |
---|---|
F5 |
|
Configuration 1 [-]
|
Configuration 2 [-]
|
Configuration 3 [-]
|
Configuration 4 [-]
|
Configuration 5 [-]
|
Configuration 6 [-]
|
Configuration 7 [-]
|
Configuration 8 [-]
|
Configuration 9 [-]
|
Configuration 10 [-]
|
Configuration 11 [-]
|
Configuration 12 [-]
|
Configuration 13 [-]
|
References
Link | Resource |
---|---|
http://www.securitytracker.com/id/1041018 | Third Party Advisory VDB Entry |
https://support.f5.com/csp/article/K00363258 | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: f5
Published: 2018-05-30T00:00:00
Updated: 2018-06-02T09:57:01
Reserved: 2018-01-12T00:00:00
Link: CVE-2018-5525
JSON object: View
NVD Information
Status : Analyzed
Published: 2018-06-01T14:29:00.690
Modified: 2018-08-01T18:48:22.123
Link: CVE-2018-5525
JSON object: View
Redhat Information
No data.
CWE