CVE-2018-5529: F5 BIG-IP Access Policy Manager
High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.
The svpn component of the F5 BIG-IP APM client prior to version 7.1.7 for Linux and Mac OS X runs as a privileged process and can allow an unprivileged user to assume super-user privileges on the local client host. A malicious local unprivileged user may gain knowledge of sensitive information, manipulate certain data, or disrupt service.
Affected products
- F5 BIG-IP Access Policy Manager: from 7.1.5, up to and including 7.1.6.1; from 11.5.1, up to and including 11.5.6; from 12.1.0, up to and including 12.1.3; from 13.0.0, up to and including 13.1.0
- F5 BIG-IP Edge: from 7101, up to and including 7150
Published 2018-07-12. Last modified 2026-06-17.