CVE-2018-5546: F5 BIG-IP Access Policy Manager

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

The svpn and policyserver components of the F5 BIG-IP APM client prior to version 7.1.7.1 for Linux and macOS runs as a privileged process and can allow an unprivileged user to get ownership of files owned by root on the local client host. A malicious local unprivileged user may gain knowledge of sensitive information, manipulate certain data, or assume super-user privileges on the local client host.

Affected products

  • F5 BIG-IP Access Policy Manager: from 12.1.0, up to and including 12.1.3
  • F5 BIG-IP Access Policy Manager Client: from 7.1.5, up to and including 7.1.7

Published 2018-08-17. Last modified 2026-06-17.