CVE-2018-5539: F5 BIG-IP Application Security Manager
High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.
Under certain conditions, on F5 BIG-IP ASM 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, 11.6.0-11.6.3.1, 11.5.1-11.5.6, or 11.2.1, when processing CSRF protections, the BIG-IP ASM bd process may restart and produce a core file.
Affected products
- F5 BIG-IP Application Security Manager: from 11.5.1, up to and including 11.5.6; from 11.6.1, up to and including 11.6.3; from 12.1.0, up to and including 12.1.3; from 13.0.0, up to and including 13.1.0; version 11.2.1 only
Published 2018-07-25. Last modified 2026-06-17.