CVE-2020-27716: High severity f5 access policy manager vulnerability
On versions 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.5, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, when a BIG-IP APM virtual server processes traffic of an undisclosed nature, the Traffic Management Microkernel (TMM) stops responding and restarts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-27716?
CVE-2020-27716 has been assigned a high severity rating due to its impact on the availability of the BIG-IP APM.
How do I fix CVE-2020-27716?
To mitigate CVE-2020-27716, upgrade your F5 BIG-IP Access Policy Manager to a patched version that is not vulnerable.
Which versions are affected by CVE-2020-27716?
CVE-2020-27716 affects F5 BIG-IP Access Policy Manager versions from 11.6.1 to 15.1.0.
What are the potential impacts of CVE-2020-27716?
CVE-2020-27716 can cause the Traffic Management Microkernel to become unresponsive and restart, leading to service disruptions.
Is there a workaround for CVE-2020-27716?
Currently, there are no documented workarounds for CVE-2020-27716, so upgrading is the best course of action.