CVE-2020-5885
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 3.9 / Impact: 5.2
Source: NVD
Description
On versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, and 12.1.0-12.1.5.1, BIG-IP systems set up for connection mirroring in a high availability (HA) pair transfer sensitive cryptographic objects over an insecure communications channel. This is a control plane issue which is exposed only on the network used for connection mirroring.
Affected (44)
Products: F5: Big Ip Access Policy Manager, Big Ip Advanced Firewall Manager, Big Ip Analytics, Big Ip Application Acceleration Manager, Big Ip Application Security Manager, Big Ip Domain Name System, Big Ip Fraud Protection Service, Big Ip Global Traffic Manager, Big Ip Link Controller, Big Ip Local Traffic Manager, Big Ip Policy Enforcement Manager
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 12.1.0 to 12.1.5.1 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 12.1.0 to 12.1.5.1 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 12.1.0 to 12.1.5.1 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 12.1.0 to 12.1.5.1 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| From 12.1.0 to 12.1.5.1 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| From 12.1.0 to 12.1.5.1 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| From 12.1.0 to 12.1.5.1 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| From 12.1.0 to 12.1.5.1 |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| From 12.1.0 to 12.1.5.1 |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| From 12.1.0 to 12.1.5.1 |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| From 12.1.0 to 12.1.5.1 |
Related CWEs
CWE-319
Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
CWE-326
Inadequate Encryption Strength
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.