CVE-2018-5518 is a medium-severity vulnerability affecting F5 BIG-IP versions 13.0.0-13.1.0.5 and 12.0.0-12.1.3.3. It allows a malicious root user on a "host-only" or "bridged" vCMP guest to disrupt service on adjacent vCMP guests on the same host, causing the vCMPd process to restart. The attack requires high privileges and network access to the adjacent guest, with a CVSS score of 5.4. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.0.0, <= 12.1.3CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:* | ||
>= 13.0.0, <= 13.1.0CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:* | ||
>= 12.0.0, <= 12.1.3CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:* | ||
>= 13.0.0, <= 13.1.0CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:* | ||
>= 12.0.0, <= 12.1.3CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.