Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
Unknown
Privileges Required
Unknown
Attack Vector
Unknown
0

CVE-2018-5521

Disclosure Date: June 01, 2018
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

On F5 BIG-IP 12.1.0-12.1.3.1, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, carefully crafted URLs can be used to reflect arbitrary content into GeoIP lookup responses, potentially exposing clients to XSS.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
None
Impact Score:
Unknown
Exploitability Score:
Unknown
Vector:
Unknown
Attack Vector (AV):
Unknown
Attack Complexity (AC):
Unknown
Privileges Required (PR):
Unknown
User Interaction (UI):
Unknown
Scope (S):
Unknown
Confidentiality (C):
Unknown
Integrity (I):
Unknown
Availability (A):
Unknown

General Information

Vendors

  • f5

Products

  • big-ip access policy manager,
  • big-ip access policy manager 11.2.1,
  • big-ip advanced firewall manager,
  • big-ip advanced firewall manager 11.2.1,
  • big-ip analytics,
  • big-ip analytics 11.2.1,
  • big-ip application acceleration manager,
  • big-ip application acceleration manager 11.2.1,
  • big-ip application security manager,
  • big-ip application security manager 11.2.1,
  • big-ip domain name system,
  • big-ip domain name system 11.2.1,
  • big-ip edge gateway,
  • big-ip edge gateway 11.2.1,
  • big-ip global traffic manager,
  • big-ip global traffic manager 11.2.1,
  • big-ip link controller,
  • big-ip link controller 11.2.1,
  • big-ip local traffic manager,
  • big-ip local traffic manager 11.2.1,
  • big-ip policy enforcement manager,
  • big-ip policy enforcement manager 11.2.1,
  • big-ip webaccelerator,
  • big-ip webaccelerator 11.2.1,
  • big-ip websafe,
  • big-ip websafe 11.2.1

Additional Info

Technical Analysis