CVE-2020-27714: High severity f5 big-ip advanced firewall manager vulnerability
On the BIG-IP AFM version 15.1.0-15.1.0.5, 14.1.0-14.1.3, and 13.1.0-13.1.3.5, when a Protocol Inspection Profile is attached to a FastL4 virtual server with the protocol field configured to either Other or All Protocols, the TMM may experience a restart if the profile processes non-TCP traffic.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-27714?
CVE-2020-27714 has a medium severity rating due to the potential for TMM restarts impacting availability.
How do I fix CVE-2020-27714?
To mitigate CVE-2020-27714, you should avoid attaching a Protocol Inspection Profile with the 'Other' or 'All Protocols' settings to FastL4 virtual servers.
What versions are affected by CVE-2020-27714?
CVE-2020-27714 affects F5 BIG-IP Advanced Firewall Manager versions 15.1.0-15.1.0.5, 14.1.0-14.1.3, and 13.1.0-13.1.3.5.
What happens if I don't address CVE-2020-27714?
If CVE-2020-27714 is not addressed, the system may experience unexpected TMM restarts, leading to potential disruption of network services.
Is there a patch available for CVE-2020-27714?
As of now, there are no specific patches mentioned for CVE-2020-27714, but updating to a non-affected version is recommended.