LiveActive security incident?Get immediate response
CVE Record

CVE-2018-5506: In F5 BIG-IP 13.0.0, 12.1.0-12.1.2, 11.6.1, 11.5.1-11.5.5, or 11.2.1 the Apache modules apache_auth_token_m...

In F5 BIG-IP 13.0.0, 12.1.0-12.1.2, 11.6.1, 11.5.1-11.5.5, or 11.2.1 the Apache modules apache_auth_token_mod and mod_auth_f5_auth_token.cpp allow possible unauthenticated bruteforce on the em_server_ip authorization parameter to obtain which SSL client certificates used for mutual authentication between BIG-IQ or Enterprise Manager (EM) and managed BIG-IP devices.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

This issue affects specific F5 BIG-IP versions and may let an unauthenticated party brute force an authorization parameter to identify SSL client certificates used in management trust relationships. The source bundle does not provide a CVSS score, confirmed exploitation, or fixed versions.

Executive priority

Treat this as a targeted management-plane exposure review rather than an emergency based on the provided evidence. Prioritize affected F5 environments because trust relationships between management systems and BIG-IP devices are operationally sensitive.

Technical view

CVE-2018-5506 concerns BIG-IP Apache authentication modules apache_auth_token_mod and mod_auth_f5_auth_token.cpp. The described weakness is possible unauthenticated brute force against the em_server_ip authorization parameter to determine SSL client certificates used for mutual authentication between BIG-IQ or Enterprise Manager and managed BIG-IP devices.

Likely exposure

Exposure is limited to listed F5 BIG-IP product lines on versions 13.0.0, 12.1.0-12.1.2, 11.6.1, 11.5.1-11.5.5, or 11.2.1, especially where BIG-IQ or Enterprise Manager manages BIG-IP devices.

Exploitation context

The bundle marks CISA KEV as false and provides no cited evidence of active exploitation. The vulnerability description indicates unauthenticated brute force is possible, but does not include exploit maturity, prerequisites beyond affected versions, or impact beyond certificate identification.

Researcher notes

Evidence is sparse: no CVSS, CWE, fixed versions, or exploit confirmation are included in the bundle. Analysis should stay anchored to F5 advisory K65355492 and the CVE record. Avoid expanding scope beyond the named BIG-IP versions and BIG-IQ or Enterprise Manager mTLS context.

Mitigation direction

  • Review F5 advisory K65355492 for vendor-confirmed fixes or workarounds.
  • Inventory BIG-IP versions against the affected version list.
  • Identify BIG-IP devices managed by BIG-IQ or Enterprise Manager.
  • Prioritize vendor-approved upgrades or hotfixes once confirmed.
  • Review management-plane exposure while awaiting vendor guidance.

Validation and detection

  • Check BIG-IP software versions against the affected ranges.
  • Confirm whether BIG-IQ or Enterprise Manager manages each device.
  • Review deployed modules and product licenses against the affected product list.
  • Document whether F5 advisory K65355492 lists a fix for each deployed version.
  • Verify no compensating control is claimed without vendor support.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2018-5506 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
F5 Networks, Inc.BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, WebAccelerator, WebSafe)13.0.0, 12.1.0-12.1.2, 11.6.1, 11.5.1-11.5.5, 11.2.1Listed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.