CVE-2020-5876
8.1
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: NVD
Description
On BIG-IP 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, a race condition exists where mcpd and other processes may make unencrypted connection attempts to a new configuration sync peer. The race condition can occur when changing the ConfigSync IP address of a peer, adding a new peer, or when the Traffic Management Microkernel (TMM) first starts up.
Affected (55)
Products: F5: Big Ip Access Policy Manager, Big Ip Advanced Firewall Manager, Big Ip Analytics, Big Ip Application Acceleration Manager, Big Ip Application Security Manager, Big Ip Domain Name System, Big Ip Fraud Protection Service, Big Ip Global Traffic Manager, Big Ip Link Controller, Big Ip Local Traffic Manager, Big Ip Policy Enforcement Manager
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.6.1 to 11.6.5.1 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.6.1 to 11.6.5.1 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.6.1 to 11.6.5.1 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.6.1 to 11.6.5.1 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.6.1 to 11.6.5.1 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.6.1 to 11.6.5.1 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.6.1 to 11.6.5.1 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.6.1 to 11.6.5.1 |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.6.1 to 11.6.5.1 |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.6.1 to 11.6.5.1 |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.6.1 to 11.6.5.1 |
Related CWEs
CWE-319
Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
The product contains a code sequence that can run concurrently with other code, and the code sequence requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence that is operating concurrently.
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.