CVE-2020-27715: High severity f5 access policy manager vulnerability
Published Dec 24, 2020
·Updated
On BIG-IP 15.1.0-15.1.0.5 and 14.1.0-14.1.3, crafted TLS request to the BIG-IP management interface via port 443 can cause high (~100%) CPU utilization by the httpd daemon.
Affected Software
22 affected components
F5 BIG-IP Access Policy Manager>=14.1.0<14.1.3.1
F5 BIG-IP Access Policy Manager>=15.0.0<15.1.1
F5 BIG-IP Advanced Firewall Manager>=14.1.0<14.1.3.1
F5 BIG-IP Advanced Firewall Manager>=15.0.0<15.1.1
F5 BIG-IP Analytics>=14.1.0<14.1.3.1
F5 BIG-IP Analytics>=15.0.0<15.1.1
F5 Big-ip Application Acceleration Manager>=14.1.0<14.1.3.1
F5 Big-ip Application Acceleration Manager>=15.0.0<15.1.1
F5 BIG-IP Application Security Manager>=14.1.0<14.1.3.1
F5 BIG-IP Application Security Manager>=15.0.0<15.1.1
F5 Big-ip Domain Name System>=14.1.0<14.1.3.1
F5 Big-ip Domain Name System>=15.0.0<15.1.1
F5 Big-ip Fraud Protection Service>=14.1.0<14.1.3.1
F5 Big-ip Fraud Protection Service>=15.0.0<15.1.1
F5 Big-ip Global Traffic Manager>=14.1.0<14.1.3.1
F5 Big-ip Global Traffic Manager>=15.0.0<15.1.1
F5 Big-ip Link Controller>=14.1.0<14.1.3.1
F5 Big-ip Link Controller>=15.0.0<15.1.1
F5 Big-ip Local Traffic Manager>=14.1.0<14.1.3.1
F5 Big-ip Local Traffic Manager>=15.0.0<15.1.1
F5 Big-ip Policy Enforcement Manager>=14.1.0<14.1.3.1
F5 Big-ip Policy Enforcement Manager>=15.0.0<15.1.1
Event History
Dec 24, 2020
CVE Published
via MITRE·03:07 PM
Data Sourced
via MITRE·03:07 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-27715?
CVE-2020-27715 has a high severity rating due to its potential to cause a denial of service by consuming nearly 100% CPU utilization.
2
How do I fix CVE-2020-27715?
To fix CVE-2020-27715, apply the vendor-provided patches for affected versions of the BIG-IP software.
3
Which versions are affected by CVE-2020-27715?
CVE-2020-27715 affects F5 BIG-IP versions 15.1.0 to 15.1.0.5 and 14.1.0 to 14.1.3.
4
What type of attack does CVE-2020-27715 facilitate?
CVE-2020-27715 facilitates a denial of service (DoS) attack against the BIG-IP management interface.
5
Is CVE-2020-27715 exploitable remotely?
Yes, CVE-2020-27715 is remotely exploitable via crafted TLS requests to the management interface on port 443.