CVE-2018-5511
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 15%
from disclosure to weapon346 days
Published on NVDApr 13
1st PoC+346d
exploitation probability
15%top 4% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
On F5 BIG-IP 13.1.0-13.1.0.3 or 13.0.0, when authenticated administrative users execute commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, restrictions on allowed commands may not be enforced.
Affected products
F5 Networks, Inc. · BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, WebAccelerator, WebSafe)public PoCs found — 3✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/46600cve_referencepacketstormsecurity.com/files/152213/VMware-Host-VMX-Process-Impersonation-Hijack-Privilege-Escalation.htmlunverifiedcve_referencewww.exploit-db.com/exploits/46600/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.