CVE-2018-5521 vulnerability in F5 Networks Products
Published on June 1, 2018
On F5 BIG-IP 12.1.0-12.1.3.1, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, carefully crafted URLs can be used to reflect arbitrary content into GeoIP lookup responses, potentially exposing clients to XSS.
Products Associated with CVE-2018-5521
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2018-5521 are published in these products:
Affected Versions
F5 Networks, Inc. BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, FPS, GTM, Link Controller, PEM, WebAccelerator):- Version 12.1.0-12.1.3.1 is affected.
- Version 11.6.1-11.6.3.1 is affected.
- Version 11.5.1-11.5.5 is affected.
- Version 11.2.1 is affected.
Exploit Probability
EPSS
0.35%
Percentile
56.65%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.