Vulnerability Details CVE-2018-5500
On F5 BIG-IP systems running 13.0.0, 12.1.0 - 12.1.3.1, or 11.6.1 - 11.6.2, every Multipath TCP (MCTCP) connection established leaks a small amount of memory. Virtual server using TCP profile with Multipath TCP (MCTCP) feature enabled will be affected by this issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 70.5%
CVSS Severity
CVSS v3 Score 5.9
CVSS v2 Score 4.3
Products affected by CVE-2018-5500
-
cpe:2.3:a:f5:big-ip_access_policy_manager:11.6.1
-
cpe:2.3:a:f5:big-ip_access_policy_manager:11.6.2
-
cpe:2.3:a:f5:big-ip_access_policy_manager:12.1.0
-
cpe:2.3:a:f5:big-ip_access_policy_manager:12.1.1
-
cpe:2.3:a:f5:big-ip_access_policy_manager:12.1.2
-
cpe:2.3:a:f5:big-ip_access_policy_manager:12.1.3
-
cpe:2.3:a:f5:big-ip_access_policy_manager:12.1.3.1
-
cpe:2.3:a:f5:big-ip_access_policy_manager:13.0.0
-
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:11.6.1
-
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:11.6.2
-
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:12.1.0
-
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:12.1.1
-
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:12.1.2
-
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:12.1.3
-
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:12.1.3.1
-
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:13.0.0
-
cpe:2.3:a:f5:big-ip_analytics:11.6.1
-
cpe:2.3:a:f5:big-ip_analytics:11.6.2
-
cpe:2.3:a:f5:big-ip_analytics:12.1.0
-
cpe:2.3:a:f5:big-ip_analytics:12.1.1
-
cpe:2.3:a:f5:big-ip_analytics:12.1.2
-
cpe:2.3:a:f5:big-ip_analytics:12.1.3
-
cpe:2.3:a:f5:big-ip_analytics:12.1.3.1
-
cpe:2.3:a:f5:big-ip_analytics:13.0.0
-
cpe:2.3:a:f5:big-ip_application_acceleration_manager:11.6.1
-
cpe:2.3:a:f5:big-ip_application_acceleration_manager:11.6.2
-
cpe:2.3:a:f5:big-ip_application_acceleration_manager:12.1.0
-
cpe:2.3:a:f5:big-ip_application_acceleration_manager:12.1.1
-
cpe:2.3:a:f5:big-ip_application_acceleration_manager:12.1.2
-
cpe:2.3:a:f5:big-ip_application_acceleration_manager:12.1.3
-
cpe:2.3:a:f5:big-ip_application_acceleration_manager:12.1.3.1
-
cpe:2.3:a:f5:big-ip_application_acceleration_manager:13.0.0
-
cpe:2.3:a:f5:big-ip_application_security_manager:11.6.1
-
cpe:2.3:a:f5:big-ip_application_security_manager:11.6.2
-
cpe:2.3:a:f5:big-ip_application_security_manager:12.1.0
-
cpe:2.3:a:f5:big-ip_application_security_manager:12.1.1
-
cpe:2.3:a:f5:big-ip_application_security_manager:12.1.2
-
cpe:2.3:a:f5:big-ip_application_security_manager:12.1.3
-
cpe:2.3:a:f5:big-ip_application_security_manager:12.1.3.1
-
cpe:2.3:a:f5:big-ip_application_security_manager:13.0.0
-
cpe:2.3:a:f5:big-ip_dns:*
-
cpe:2.3:a:f5:big-ip_dns:12.1.0
-
cpe:2.3:a:f5:big-ip_dns:12.1.1
-
cpe:2.3:a:f5:big-ip_dns:12.1.2
-
cpe:2.3:a:f5:big-ip_dns:13.0.0
-
cpe:2.3:a:f5:big-ip_edge_gateway:11.6.1
-
cpe:2.3:a:f5:big-ip_edge_gateway:11.6.2
-
cpe:2.3:a:f5:big-ip_edge_gateway:12.1.0
-
cpe:2.3:a:f5:big-ip_edge_gateway:12.1.1
-
cpe:2.3:a:f5:big-ip_edge_gateway:12.1.2
-
cpe:2.3:a:f5:big-ip_edge_gateway:12.1.3
-
cpe:2.3:a:f5:big-ip_edge_gateway:12.1.3.1
-
cpe:2.3:a:f5:big-ip_edge_gateway:13.0.0
-
cpe:2.3:a:f5:big-ip_global_traffic_manager:11.6.1
-
cpe:2.3:a:f5:big-ip_global_traffic_manager:11.6.2
-
cpe:2.3:a:f5:big-ip_global_traffic_manager:12.1.0
-
cpe:2.3:a:f5:big-ip_global_traffic_manager:12.1.1
-
cpe:2.3:a:f5:big-ip_global_traffic_manager:12.1.2
-
cpe:2.3:a:f5:big-ip_global_traffic_manager:12.1.3
-
cpe:2.3:a:f5:big-ip_global_traffic_manager:12.1.3.1
-
cpe:2.3:a:f5:big-ip_global_traffic_manager:13.0.0
-
cpe:2.3:a:f5:big-ip_link_controller:11.6.1
-
cpe:2.3:a:f5:big-ip_link_controller:11.6.2
-
cpe:2.3:a:f5:big-ip_link_controller:12.1.0
-
cpe:2.3:a:f5:big-ip_link_controller:12.1.1
-
cpe:2.3:a:f5:big-ip_link_controller:12.1.2
-
cpe:2.3:a:f5:big-ip_link_controller:12.1.3
-
cpe:2.3:a:f5:big-ip_link_controller:12.1.3.1
-
cpe:2.3:a:f5:big-ip_link_controller:13.0.0
-
cpe:2.3:a:f5:big-ip_local_traffic_manager:11.6.1
-
cpe:2.3:a:f5:big-ip_local_traffic_manager:11.6.2
-
cpe:2.3:a:f5:big-ip_local_traffic_manager:12.1.0
-
cpe:2.3:a:f5:big-ip_local_traffic_manager:12.1.1
-
cpe:2.3:a:f5:big-ip_local_traffic_manager:12.1.2
-
cpe:2.3:a:f5:big-ip_local_traffic_manager:12.1.3
-
cpe:2.3:a:f5:big-ip_local_traffic_manager:12.1.3.1
-
cpe:2.3:a:f5:big-ip_local_traffic_manager:13.0.0
-
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:11.6.1
-
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:11.6.2
-
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:12.1.0
-
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:12.1.1
-
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:12.1.2
-
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:12.1.3
-
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:12.1.3.1
-
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:13.0.0
-
cpe:2.3:a:f5:big-ip_webaccelerator:11.6.1
-
cpe:2.3:a:f5:big-ip_webaccelerator:11.6.2
-
cpe:2.3:a:f5:big-ip_webaccelerator:12.1.0
-
cpe:2.3:a:f5:big-ip_webaccelerator:12.1.1
-
cpe:2.3:a:f5:big-ip_webaccelerator:12.1.2
-
cpe:2.3:a:f5:big-ip_webaccelerator:12.1.3
-
cpe:2.3:a:f5:big-ip_webaccelerator:12.1.3.1
-
cpe:2.3:a:f5:big-ip_webaccelerator:13.0.0
-
cpe:2.3:a:f5:big-ip_websafe:11.6.1
-
cpe:2.3:a:f5:big-ip_websafe:11.6.2
-
cpe:2.3:a:f5:big-ip_websafe:12.1.0
-
cpe:2.3:a:f5:big-ip_websafe:12.1.1
-
cpe:2.3:a:f5:big-ip_websafe:12.1.2
-
cpe:2.3:a:f5:big-ip_websafe:12.1.3
-
cpe:2.3:a:f5:big-ip_websafe:13.0.0