CVE-2018-15318
Last modified
CVE-2018-15318 is a vulnerability of currently unknown severity. In BIG-IP 14.0.0-14.0.0.2, 13.1.0.4-13.1.1.1, or 12.1.3.4-12.1.3.6, If an MPTCP connection receives an abort signal while the initial flow is not the primary flow, the initial flow will remain after the closing procedure is complete. TMM may restart and produce a core file as a result of this condition.. EPSS estimates a 1.34% chance of exploitation in the next 30 days.
Description
In BIG-IP 14.0.0-14.0.0.2, 13.1.0.4-13.1.1.1, or 12.1.3.4-12.1.3.6, If an MPTCP connection receives an abort signal while the initial flow is not the primary flow, the initial flow will remain after the closing procedure is complete. TMM may restart and produce a core file as a result of this condition.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| F5 | Big-Ip Local Traffic Manager | >= 12.1.3.4, <= 12.1.3.6 |
| F5 | Big-Ip Local Traffic Manager | >= 13.0.0, <= 13.1.1.1 |
| F5 | Big-Ip Local Traffic Manager | >= 14.0.0, <= 14.0.0.2 |
| F5 | Big-Ip Advanced Firewall Manager | >= 12.1.3.4, <= 12.1.3.6 |
| F5 | Big-Ip Advanced Firewall Manager | >= 13.0.0, <= 13.1.1.1 |
| F5 | Big-Ip Advanced Firewall Manager | >= 14.0.0, <= 14.0.0.2 |
| F5 | Big-Ip Application Acceleration Manager | >= 12.1.3.4, <= 12.1.3.6 |
| F5 | Big-Ip Application Acceleration Manager | >= 13.0.0, <= 13.1.1.1 |
| F5 | Big-Ip Application Acceleration Manager | >= 14.0.0, <= 14.0.0.2 |
| F5 | Big-Ip Analytics | >= 12.1.3.4, <= 12.1.3.6 |
| F5 | Big-Ip Analytics | >= 13.0.0, <= 13.1.1.1 |
| F5 | Big-Ip Analytics | >= 14.0.0, <= 14.0.0.2 |
| F5 | Big-Ip Access Policy Manager | >= 12.1.3.4, <= 12.1.3.6 |
| F5 | Big-Ip Access Policy Manager | >= 13.0.0, <= 13.1.1.1 |
| F5 | Big-Ip Access Policy Manager | >= 14.0.0, <= 14.0.0.2 |
| F5 | Big-Ip Protocol Security Module | >= 12.1.3.4, <= 12.1.3.6 |
| F5 | Big-Ip Protocol Security Module | >= 13.0.0, <= 13.1.1.1 |
| F5 | Big-Ip Protocol Security Module | >= 14.0.0, <= 14.0.0.2 |
| F5 | Big-Ip Domain Name System | >= 12.1.3.4, <= 12.1.3.6 |
| F5 | Big-Ip Domain Name System | >= 13.0.0, <= 13.1.1.1 |
| F5 | Big-Ip Domain Name System | >= 14.0.0, <= 14.0.0.2 |
| F5 | Big-Ip Edge Gateway | >= 12.1.3.4, <= 12.1.3.6 |
| F5 | Big-Ip Edge Gateway | >= 13.0.0, <= 13.1.1.1 |
| F5 | Big-Ip Edge Gateway | >= 14.0.0, <= 14.0.0.2 |
| F5 | Big-Ip Fraud Protection Service | >= 12.1.3.4, <= 12.1.3.6 |
| F5 | Big-Ip Fraud Protection Service | >= 13.0.0, <= 13.1.1.1 |
| F5 | Big-Ip Fraud Protection Service | >= 14.0.0, <= 14.0.0.2 |
| F5 | Big-Ip Global Traffic Manager | >= 12.1.3.4, <= 12.1.3.6 |
| F5 | Big-Ip Global Traffic Manager | >= 13.0.0, <= 13.1.1.1 |
| F5 | Big-Ip Global Traffic Manager | >= 14.0.0, <= 14.0.0.2 |
| F5 | Big-Ip Link Controller | >= 12.1.3.4, <= 12.1.3.6 |
| F5 | Big-Ip Link Controller | >= 13.0.0, <= 13.1.1.1 |
| F5 | Big-Ip Link Controller | >= 14.0.0, <= 14.0.0.2 |
| F5 | Big-Ip Policy Enforcement Manager | >= 12.1.3.4, <= 12.1.3.6 |
| F5 | Big-Ip Policy Enforcement Manager | >= 13.0.0, <= 13.1.1.1 |
| F5 | Big-Ip Policy Enforcement Manager | >= 14.0.0, <= 14.0.0.2 |
| F5 | Big-Ip Webaccelerator | >= 12.1.3.4, <= 12.1.3.6 |
| F5 | Big-Ip Webaccelerator | >= 13.0.0, <= 13.1.1.1 |
| F5 | Big-Ip Webaccelerator | >= 14.0.0, <= 14.0.0.2 |
References
- https://support.f5.com/csp/article/K16248201Vendor Advisory
- https://support.f5.com/csp/article/K16248201Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-15318?
How severe is CVE-2018-15318?
How do I fix CVE-2018-15318?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-15312On F5 BIG-IP 13.0.0-13.1.1.1 and 12.1.0-12.1.3.6, a reflecte…
- CVE-2018-15313On F5 BIG-IP AFM 13.0.0-13.1.1.1 and 12.1.0-12.1.3.6, there …
- CVE-2018-15314On F5 BIG-IP AFM 13.0.0-13.1.1.1 and 12.1.0-12.1.3.6, there …
- CVE-2018-15315On F5 BIG-IP 13.0.0-13.1.1.1 and 12.1.0-12.1.3.6, there is a…
- CVE-2018-15316In F5 BIG-IP APM 13.0.0-13.1.1.1, APM Client 7.1.5-7.1.6, an…
- CVE-2018-15317In BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1,…
- CVE-2018-15319On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.1, or 12.1.0-12.1.3…
- CVE-2018-1532IBM API Connect 5.0.0.0 through 5.0.8.2 does not properly up…4.3
- CVE-2018-15320On BIG-IP 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1, undisclosed tr…
- CVE-2018-15321When BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.0.5, 12.1.0-12.1.3.…
- CVE-2018-15322On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.0.7, 12.1.0-12.1.3.5,…
- CVE-2018-15323On BIG-IP 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1, in certain cir…
Are you affected by CVE-2018-15318?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
