Virtual Server Gzip Bomb Vulnerability on BIG-IP Systems

Virtual Server Gzip Bomb Vulnerability on BIG-IP Systems

CVE-2018-15330 · HIGH Severity

AV:N/AC:L/AU:N/C:N/I:N/A:C

On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.1, or 12.1.0-12.1.3.7, when a virtual server using the inflate functionality to process a gzip bomb as a payload, the BIG-IP system will experience a fatal error and may cause the Traffic Management Microkernel (TMM) to produce a core file.

Learn more about our Cis Benchmark Audit For Server Software.