Vulnerabilities > CVE-2018-5529 - Unspecified vulnerability in F5 Big-Ip Access Policy Manager and Big-Ip Edge
Attack vector
LOCAL Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
The svpn component of the F5 BIG-IP APM client prior to version 7.1.7 for Linux and Mac OS X runs as a privileged process and can allow an unprivileged user to assume super-user privileges on the local client host. A malicious local unprivileged user may gain knowledge of sensitive information, manipulate certain data, or disrupt service.
Vulnerable Configurations
Nessus
NASL family | F5 Networks Local Security Checks |
NASL id | F5_BIGIP_SOL52171282.NASL |
description | The svpn component of the F5 BIG-IP APM client prior to version 7.1.7 for Linux and Mac OS X runs as a privileged process and can allow an unprivileged user to assume super-user privileges on the local client host. A malicious local unprivileged user may gain knowledge of sensitive information, manipulate certain data, or disrupt service. (CVE-2018-5529) Impact A malicious, local, unprivileged user may gain knowledge of sensitive information, manipulate certain data, or disrupt service. |
last seen | 2020-03-17 |
modified | 2018-11-02 |
plugin id | 118676 |
published | 2018-11-02 |
reporter | This script is Copyright (C) 2018-2020 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/118676 |
title | F5 Networks BIG-IP : BIG-IP APM client for Linux and macOS vulnerability (K52171282) |
code |
|
References
- http://www.securityfocus.com/bid/104730
- http://www.securityfocus.com/bid/104730
- https://github.com/mirchr/security-research/blob/master/vulnerabilities/F5/CVE-2018-5529.txt
- https://github.com/mirchr/security-research/blob/master/vulnerabilities/F5/CVE-2018-5529.txt
- https://support.f5.com/csp/article/K52171282
- https://support.f5.com/csp/article/K52171282