CVE-2018-5541: F5 BIG-IP Application Security Manager

High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.

When F5 BIG-IP ASM 13.0.0-13.1.0.1, 12.1.0-12.1.3.5, 11.6.0-11.6.3.1, or 11.5.1-11.5.6 is processing HTTP requests, an unusually large number of parameters can cause excessive CPU usage in the BIG-IP ASM bd process.

Affected products

  • F5 BIG-IP Application Security Manager: from 11.5.1, up to and including 11.5.5; from 11.6.1, up to and including 11.6.3; from 12.1.0, up to and including 12.1.3; from 13.0.0, up to and including 13.1.0

Published 2018-07-25. Last modified 2026-06-17.