CVE-2018-5502: F5 BIG-IP Access Policy Manager

High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.

On F5 BIG-IP versions 13.0.0 - 13.1.0.3, attackers may be able to disrupt services on the BIG-IP system with maliciously crafted client certificate. This vulnerability affects virtual servers associated with Client SSL profile which enables the use of client certificate authentication. Client certificate authentication is not enabled by default in Client SSL profile. There is no control plane exposure.

Affected products

  • F5 BIG-IP Access Policy Manager: from 13.0.0, before 13.1.0.4 (fixed in 13.1.0.4)
  • F5 BIG-IP Advanced Firewall Manager: from 13.0.0, before 13.1.0.4 (fixed in 13.1.0.4)
  • F5 BIG-IP Analytics: from 13.0.0, before 13.1.0.4 (fixed in 13.1.0.4)
  • F5 BIG-IP Application Acceleration Manager: from 13.0.0, before 13.1.0.4 (fixed in 13.1.0.4)
  • F5 BIG-IP Application Security Manager: from 13.0.0, before 13.1.0.4 (fixed in 13.1.0.4)
  • F5 BIG-IP Domain Name System: from 13.0.0, up to and including 13.1.0.4
  • F5 BIG-IP Edge Gateway: from 13.0.0, before 13.1.0.4 (fixed in 13.1.0.4)
  • F5 BIG-IP Global Traffic Manager: from 13.0.0, before 13.1.0.4 (fixed in 13.1.0.4)
  • F5 BIG-IP Link Controller: from 13.0.0, before 13.1.0.4 (fixed in 13.1.0.4)
  • F5 BIG-IP Local Traffic Manager: from 13.0.0, before 13.1.0.4 (fixed in 13.1.0.4)
  • F5 BIG-IP Policy Enforcement Manager: from 13.0.0, before 13.1.0.4 (fixed in 13.1.0.4)
  • F5 BIG-IP Webaccelerator: from 13.0.0, before 13.1.0.4 (fixed in 13.1.0.4)
  • F5 BIG-IP Websafe: version 1.0.0 only

Published 2018-03-22. Last modified 2026-06-17.