CVE-2018-5514: F5 BIG-IP Access Policy Manager
High severity, CVSS 7.5. EPSS: 3.9% chance of exploitation in the next 30 days.
On F5 BIG-IP 13.1.0-13.1.0.5, maliciously crafted HTTP/2 request frames can lead to denial of service. There is data plane exposure for virtual servers when the HTTP2 profile is enabled. There is no control plane exposure to this issue.
Affected products
- F5 BIG-IP Access Policy Manager: from 13.1.0, up to and including 13.1.0.5
- F5 BIG-IP Advanced Firewall Manager: from 13.1.0, up to and including 13.1.0.5
- F5 BIG-IP Analytics: from 13.1.0, up to and including 13.1.0.5
- F5 BIG-IP Application Acceleration Manager: from 13.1.0, up to and including 13.1.0.5
- F5 BIG-IP Application Security Manager: from 13.1.0, up to and including 13.1.0.5
- F5 BIG-IP Domain Name System: from 13.1.0, up to and including 13.1.0.5
- F5 BIG-IP Edge Gateway: from 13.1.0, up to and including 13.1.0.5
- F5 BIG-IP Global Traffic Manager: from 13.1.0, up to and including 13.1.0.5
- F5 BIG-IP Link Controller: from 13.1.0, up to and including 13.1.0.5
- F5 BIG-IP Local Traffic Manager: from 13.1.0, up to and including 13.1.0.5
- F5 BIG-IP Policy Enforcement Manager: from 13.1.0, up to and including 13.1.0.5
- F5 BIG-IP Webaccelerator: from 13.1.0, up to and including 13.1.0.5
- F5 BIG-IP Websafe: from 13.1.0, up to and including 13.1.0.5
Published 2018-05-02. Last modified 2026-06-17.