CVE-2018-17539: F5 BIG-IP Local Traffic Manager

High severity, CVSS 7.5. EPSS: 2.2% chance of exploitation in the next 30 days.

The BGP daemon (bgpd) in all IP Infusion ZebOS versions to 7.10.6 and all OcNOS versions to 1.3.3.145 allow remote attackers to cause a denial of service attack via an autonomous system (AS) path containing 8 or more autonomous system number (ASN) elements.

Affected products

  • F5 BIG-IP Local Traffic Manager: from 11.2.1, up to and including 11.6.3; from 12.1.0, up to and including 12.1.3; from 13.0.0, up to and including 13.1.1; version 14.0.0 only
  • Ipinfusion Ocnos: up to and including 1.3.3.145
  • Ipinfusion Zebos: up to and including 7.10.6

Published 2018-12-28. Last modified 2026-06-17.