F5 BIG-IP Protocol Security Module 13.1.1

CPE Details

F5 BIG-IP Protocol Security Module 13.1.1
13.1.1
2019-02-27
13h11 +00:00
2019-02-27
13h11 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:f5:big-ip_protocol_security_module:13.1.1:*:*:*:*:*:*:*

Informations

Vendor

f5

Product

big-ip_protocol_security_module

Version

13.1.1

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2018-15318 2018-10-31 13h00 +00:00 In BIG-IP 14.0.0-14.0.0.2, 13.1.0.4-13.1.1.1, or 12.1.3.4-12.1.3.6, If an MPTCP connection receives an abort signal while the initial flow is not the primary flow, the initial flow will remain after the closing procedure is complete. TMM may restart and produce a core file as a result of this condition.
7.5
High
CVE-2018-15319 2018-10-31 13h00 +00:00 On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.1, or 12.1.0-12.1.3.6, malicious requests made to virtual servers with an HTTP profile can cause the TMM to restart. The issue is exposed with the non-default "normalize URI" configuration options used in iRules and/or BIG-IP LTM policies.
7.5
High
CVE-2018-15320 2018-10-31 13h00 +00:00 On BIG-IP 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1, undisclosed traffic patterns may lead to denial of service conditions for the BIG-IP system. The configuration which exposes this condition is the BIG-IP self IP address which is part of a VLAN group and has the Port Lockdown setting configured with anything other than "allow-all".
7.5
High
CVE-2018-15323 2018-10-31 13h00 +00:00 On BIG-IP 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1, in certain circumstances, when processing traffic through a Virtual Server with an associated MQTT profile, the TMM process may produce a core file and take the configured HA action.
5.9
Medium
CVE-2018-15325 2018-10-31 13h00 +00:00 In BIG-IP 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1, iControl and TMSH usage by authenticated users may leak a small amount of memory when executing commands
4.3
Medium
CVE-2018-15327 2018-10-31 13h00 +00:00 In BIG-IP 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1 or Enterprise Manager 3.1.1, when authenticated administrative users run commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, restrictions on allowed commands may not be enforced.
7.2
High