QID 379446

Date Published: 2024-03-06

QID 379446: F5 BIG-IP tcpdump Multiple Vulnerabilities (K56551263)

CVE-2018-14880: The OSPFv3 parser in tcpdump has a buffer over-read in print-ospf6.c:ospf6_print_lshdr().
BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, FPS, GTM, Link Controller, PEM, WebAccelerator) are affected to this vulnerbaility.

Affected Versions:
F5 BIG-IP version 15.0.0 - 15.1.2
F5 BIG-IP version 14.0.0 - 14.1.3
F5 BIG-IP version 13.1.0 - 13.1.4
F5 BIG-IP version 12.1.0 - 12.1.6
F5 BIG-IP version 11.5.2 - 11.6.5

QID Detection Logic (Authenticated):
This QID checks for vulnerable version of F5 BIG-IP by running the 'tmsh -q show /sys version' command.

On successful exploitation an attacker can gain access to sensitive information and can also cause a denial of service (DoS).

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Please check the fixed versions released by the vendor in K56551263
    Vendor References

    CVEs related to QID 379446

    Software Advisories
    Advisory ID Software Component Link
    K56551263 URL Logo my.f5.com/manage/s/article/K56551263