SB2018062913 - Multiple vulnerabilities in F5 BIG-IP



SB2018062913 - Multiple vulnerabilities in F5 BIG-IP

Published: June 29, 2018 Updated: July 4, 2018

Security Bulletin ID SB2018062913
Severity
Low
Patch available
YES
Number of vulnerabilities 6
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 6 secuirty vulnerabilities.


1) Resource exhaustion (CVE-ID: CVE-2018-5527)

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The vulnerability exists in virtual servers configured with a Client SSL or Server SSL profile due to a flaw in the SSL Forward Proxy feature. A remote unauthenticated attacker can cause the target Traffic Management Microkernel (TMM) to consume excessive memory and cause performance degradation or a system reboot.


2) Improper input validation (CVE-ID: CVE-2018-5528)

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The vulnerability exists due to insufficient input validation. A remote unauthenticated attacker can send specially crafted BIG-IP APM data and cause the target Traffic Management Microkernel (TMM) to restart.


3) Improper input validation (CVE-ID: CVE-2018-5522)

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists due to an error when when processing DIAMETER transactions. A remote attacker can supply specially crafted attribute-value pairs and cause TMM to crash.

4) Denial of service (CVE-ID: CVE-2017-6153)

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists due to a flaw in features that utilizes inflate functionality directly. A remote attacker can use an iRule, or the inflate code from PEM module, conduct a "Zip Bomb" attack and cause the service to crash.

5) Information disclosure (CVE-ID: CVE-2018-5525)

The vulnerability allows a local attacker to obtain potentially sensitive information on the target system.
The weakness exists in the F5 BIG-IP Configuration utility due to exposure of files containing F5-provided data only. A local attacker can gain access to arbitrary data.


6) Command injection (CVE-ID: CVE-2018-5523)

The vulnerability allows a remote administrative attacker to execute arbitrary commands on the target system.
The weakness exists due to command injection. A remote attacker can inject and run arbitrary commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility.


Remediation

Install update from vendor's website.