« Volver al listado

CVE-2018-5514

Estado: ModificadaAlta (7.5)—

On F5 BIG-IP 13.1.0-13.1.0.5, maliciously crafted HTTP/2 request frames can lead to denial of service. There is data plane exposure for virtual servers when the HTTP2 profile is enabled. There is no control plane exposure to this issue.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (13)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2018-5514",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "f5sirt@f5.com",
      "affectedData": [
        {
          "vendor": "F5 Networks, Inc.",
          "product": "BIG-IP (LTM, AAM, AFM, APM, ASM, Link Controller, PEM, WebAccelerator, WebSafe)",
          "versions": [
            {
              "status": "affected",
              "version": "13.1.0-13.1.0.5"
            }
          ]
        }
      ]
    }
  ],
  "published": "2018-05-02T13:29:00.473",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/104097",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "f5sirt@f5.com"
    },
    {
      "url": "http://www.securitytracker.com/id/1040804",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "f5sirt@f5.com"
    },
    {
      "url": "https://support.f5.com/csp/article/K45320419",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "f5sirt@f5.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/104097",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id/1040804",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.f5.com/csp/article/K45320419",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "On F5 BIG-IP 13.1.0-13.1.0.5, maliciously crafted HTTP/2 request frames can lead to denial of service. There is data plane exposure for virtual servers when the HTTP2 profile is enabled. There is no control plane exposure to this issue."
    },
    {
      "lang": "es",
      "value": "En F5 BIG-IP 13.1.0-13.1.0.5, los frames de petición HTTP/2 maliciosamente manipulados pueden conducir a una denegación de servicio (DoS). Hay una exposición del plano de datos para los servidores virtuales cuando el perfil HTTP2 está habilitado. No hay ninguna exposición del plano de control en este problema."
    }
  ],
  "lastModified": "2026-06-17T02:00:26.817",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C0C28735-736C-43BC-BA38-FD3C83A0F933",
              "versionEndIncluding": "13.1.0.5",
              "versionStartIncluding": "13.1.0"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7EA7F3C5-BDF5-4F09-8539-8FEF155DEBBD",
              "versionEndIncluding": "13.1.0.5",
              "versionStartIncluding": "13.1.0"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8965C4F2-B91D-429C-8231-FF9E3536D954",
              "versionEndIncluding": "13.1.0.5",
              "versionStartIncluding": "13.1.0"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D672C28D-61E4-448A-9F42-17CE7A202052",
              "versionEndIncluding": "13.1.0.5",
              "versionStartIncluding": "13.1.0"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "45D23A0F-BD8C-467D-988B-50B8167147D7",
              "versionEndIncluding": "13.1.0.5",
              "versionStartIncluding": "13.1.0"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D3FB756F-82F2-4E38-82C2-A09DB6CC6255",
              "versionEndIncluding": "13.1.0.5",
              "versionStartIncluding": "13.1.0"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:f5:big-ip_edge_gateway:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "72B0CAC3-BD37-4CCA-BD71-58402047A464",
              "versionEndIncluding": "13.1.0.5",
              "versionStartIncluding": "13.1.0"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8201E285-E857-4E87-BA60-A9C90087F653",
              "versionEndIncluding": "13.1.0.5",
              "versionStartIncluding": "13.1.0"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7F5EDCB6-9383-4C4B-99A9-B0ADE8934395",
              "versionEndIncluding": "13.1.0.5",
              "versionStartIncluding": "13.1.0"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "14FBF622-D5C1-4E65-8948-1F4196DF8876",
              "versionEndIncluding": "13.1.0.5",
              "versionStartIncluding": "13.1.0"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "60996909-BD94-426B-8787-7B863EE1EFD4",
              "versionEndIncluding": "13.1.0.5",
              "versionStartIncluding": "13.1.0"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:f5:big-ip_websafe:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3E182512-CCEE-45F9-958F-73CC8C8444FA",
              "versionEndIncluding": "13.1.0.5",
              "versionStartIncluding": "13.1.0"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0369EC5B-1EF3-428E-9C22-2C64BECE84EB",
              "versionEndIncluding": "13.1.0.5",
              "versionStartIncluding": "13.1.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "f5sirt@f5.com"
}