On F5 BIG-IP DNS 13.1.0-13.1.0.7, 12.1.3-12.1.3.5, DNS Express / DNS Zones accept NOTIFY messages on the management interface from source IP addresses not listed in the 'Allow NOTIFY From' configuration parameter when the db variable "dnsexpress.notifyport" is set to any value other than the default of "0".
References
Link | Resource |
---|---|
https://support.f5.com/csp/article/K45435121 | Mitigation Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Information
Published : 2018-07-25 07:29
Updated : 2019-10-02 17:03
NVD link : CVE-2018-5538
Mitre link : CVE-2018-5538
JSON object : View
CWE
Products Affected
f5
- big-ip_domain_name_system
- big-ip_link_controller
- big-ip_global_traffic_manager
- big-ip_local_traffic_manager