LiveActive security incident?Get immediate response
CVE Record

CVE-2018-15330: On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.1, or 12.1.0-12.1.3.7, when a virtual server using the inflate fun...

On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.1, or 12.1.0-12.1.3.7, when a virtual server using the inflate functionality to process a gzip bomb as a payload, the BIG-IP system will experience a fatal error and may cause the Traffic Management Microkernel (TMM) to produce a core file.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

This flaw can crash affected F5 BIG-IP traffic handling when a configured virtual server processes a gzip bomb through inflate functionality. For businesses, the concern is service availability, not confirmed data theft. Exposure depends on running listed BIG-IP versions and using the affected inflate behavior.

Executive priority

Treat as a targeted availability risk for affected F5 edge infrastructure. Prioritize if BIG-IP fronts critical applications and uses inflate processing, but current evidence does not support emergency exploitation claims.

Technical view

CVE-2018-15330 affects BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.1, and 12.1.0-12.1.3.7. A gzip bomb payload processed by virtual server inflate functionality can trigger a fatal error and may cause TMM to generate a core file.

Likely exposure

Likely exposed systems are affected BIG-IP deployments with virtual servers configured to use inflate functionality. The source bundle does not identify exposure for unaffected versions or configurations without this processing path.

Exploitation context

The source bundle does not show KEV listing, active exploitation, public exploit use, or weaponized details. It describes a denial-of-service condition triggered by processing a gzip bomb payload in a specific BIG-IP configuration.

Researcher notes

Key missing data includes CVSS, CWE classification, exploit maturity, and explicit remediation details in the provided bundle. Analysis should stay tied to the configuration condition and F5 advisory until vendor guidance is reviewed.

Mitigation direction

  • Check F5 advisory K23328310 for fixed versions, hotfixes, and supported workarounds.
  • Inventory BIG-IP appliances and compare versions against the affected release ranges.
  • Identify virtual servers using inflate functionality and assess business need.
  • Prioritize vendor-supported upgrade or mitigation for internet-facing affected virtual servers.

Validation and detection

  • Confirm BIG-IP version and module deployment against the affected ranges.
  • Review virtual server profiles or policies for inflate functionality use.
  • Check logs and crash records for TMM fatal errors or core file generation.
  • Verify remediation status against F5 advisory K23328310.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2018-15330 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
F5 Networks, Inc.BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, FPS, GTM, Link Controller, PEM, WebAccelerator)14.0.0-14.0.0.2, 13.0.0-13.1.1.1, 12.1.0-12.1.3.7Listed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.