CVE-2018-5546
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The svpn and policyserver components of the F5 BIG-IP APM client prior to version 7.1.7.1 for Linux and macOS runs as a privileged process and can allow an unprivileged user to get ownership of files owned by root on the local client host. A malicious local unprivileged user may gain knowledge of sensitive information, manipulate certain data, or assume super-user privileges on the local client host.
Los componentes svpn y policyserver del cliente F5 BIG-IP APM en versiones anteriores a la 7.1.7.1 para Linux y macOS se ejecutan como un proceso privilegiado y pueden permitir que un usuario sin privilegios obtenga la propiedad de archivos propiedad de root en el host del cliente local. Un usuario local no privilegiado malicioso puede adquirir conocimiento de informaciĆ³n sensible, manipular determinados datos o asumir privilegios de superusuario en el host del cliente local.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-01-12 CVE Reserved
- 2018-08-17 CVE Published
- 2023-08-11 EPSS Updated
- 2024-09-17 CVE Updated
- 2024-09-17 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-732: Incorrect Permission Assignment for Critical Resource
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securitytracker.com/id/1041510 | Broken Link |
URL | Date | SRC |
---|---|---|
https://github.com/mirchr/security-research/blob/master/vulnerabilities/F5/CVE-2018-5529.txt | 2024-09-17 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://support.f5.com/csp/article/K54431371 | 2022-04-18 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
F5 Search vendor "F5" | Big-ip Access Policy Manager Client Search vendor "F5" for product "Big-ip Access Policy Manager Client" | >= 7.1.5 <= 7.1.7 Search vendor "F5" for product "Big-ip Access Policy Manager Client" and version " >= 7.1.5 <= 7.1.7" | - |
Affected
| in | Apple Search vendor "Apple" | Macos Search vendor "Apple" for product "Macos" | - | - |
Safe
|
F5 Search vendor "F5" | Big-ip Access Policy Manager Client Search vendor "F5" for product "Big-ip Access Policy Manager Client" | >= 7.1.5 <= 7.1.7 Search vendor "F5" for product "Big-ip Access Policy Manager Client" and version " >= 7.1.5 <= 7.1.7" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | - | - |
Safe
|
F5 Search vendor "F5" | Big-ip Access Policy Manager Search vendor "F5" for product "Big-ip Access Policy Manager" | >= 12.1.0 <= 12.1.3 Search vendor "F5" for product "Big-ip Access Policy Manager" and version " >= 12.1.0 <= 12.1.3" | - |
Affected
| in | Apple Search vendor "Apple" | Macos Search vendor "Apple" for product "Macos" | - | - |
Safe
|
F5 Search vendor "F5" | Big-ip Access Policy Manager Search vendor "F5" for product "Big-ip Access Policy Manager" | >= 12.1.0 <= 12.1.3 Search vendor "F5" for product "Big-ip Access Policy Manager" and version " >= 12.1.0 <= 12.1.3" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | - | - |
Safe
|