CVE-2020-5860
8.1
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: NVD
Description
On BIG-IP 15.0.0-15.1.0.2, 14.1.0-14.1.2.3, 13.1.0-13.1.3.2, 12.1.0-12.1.5.1, and 11.5.2-11.6.5.1 and BIG-IQ 7.0.0, 6.0.0-6.1.0, and 5.2.0-5.4.0, in a High Availability (HA) network failover in Device Service Cluster (DSC), the failover service does not require a strong form of authentication and HA network failover traffic is not encrypted by Transport Layer Security (TLS).
Affected (58)
Products: F5: Big Iq Centralized Management, Big Ip Access Policy Manager, Big Ip Advanced Firewall Manager, Big Ip Analytics, Big Ip Application Acceleration Manager, Big Ip Application Security Manager, Big Ip Domain Name System, Big Ip Fraud Protection Service, Big Ip Global Traffic Manager, Big Ip Link Controller, Big Ip Local Traffic Manager, Big Ip Policy Enforcement Manager
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 5.2.0 to 5.4.0 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.2 to 11.6.5 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.2 to 11.6.5 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.2 to 11.6.5 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.2 to 11.6.5 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.2 to 11.6.5 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.2 to 11.6.5 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.2 to 11.6.5 |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.2 to 11.6.5 |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.2 to 11.6.5 |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.2 to 11.6.5 |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.2 to 11.6.5 |
Related CWEs
CWE-287
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CWE-319
Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.