Code Execution Vulnerability in F5 WebSafe Alert Server
CVE-2018-5545

8.8HIGH

Key Information:

Vendor
F5
Vendor
CVE Published:
13 September 2018

Summary

A vulnerability exists in the F5 WebSafe Alert Server versions 1.0.0 through 4.2.6, wherein an authenticated user can execute arbitrary code on the server by sending a specially crafted payload. This defect poses a significant risk as it allows potentially harmful operations to be carried out on the server, compromising its integrity and the security of the data it manages. Organizations utilizing this software should review their implementations and apply the latest security updates to mitigate the risk.

Affected Version(s)

F5 WebSafe Alert Server 1.0.0-4.2.6

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.