CVE-2018-5537 is a medium-severity vulnerability affecting F5 BIG-IP products across several versions (11.2.1-13.1.0.5) when a TMM virtual server is configured with an HTML or Rewrite profile. A remote attacker can disrupt services by causing the Traffic Management Microkernel (TMM) to restart through specially crafted HTML content from the backend. The attack complexity is high, requiring user interaction, but can lead to a denial of service. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 11.2.1, <= 11.5.6CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:* | ||
>= 11.6.0, <= 11.6.3.1CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:* | ||
>= 12.1.0, <= 12.1.3.5CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:* | ||
>= 13.0.0, <= 13.1.0.5CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:* | ||
>= 11.2.1, <= 11.5.6CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.