CVE-2020-27718: High severity f5 big-ip advanced waf/asm vulnerability
When a BIG-IP ASM or Advanced WAF system running version 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, or 11.6.1-11.6.5.2 processes requests with JSON payload, an unusually large number of parameters can cause excessive CPU usage in the BIG-IP ASM bd process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-27718?
The severity of CVE-2020-27718 is classified as high due to its potential to cause excessive CPU usage, impacting system performance.
How do I fix CVE-2020-27718?
To mitigate CVE-2020-27718, upgrade to a non-vulnerable version of F5 BIG-IP Advanced WAF or Application Security Manager, specifically versions above those indicated in the vulnerability disclosure.
What products are affected by CVE-2020-27718?
CVE-2020-27718 affects various versions of F5 BIG-IP Advanced WAF and Application Security Manager from version 11.6.1 to 16.0.0.
What symptoms indicate an exploitation of CVE-2020-27718?
Symptoms of CVE-2020-27718 exploitation may include unusually high CPU usage and potential performance degradation in the affected system.
Is there a workaround for CVE-2020-27718 if I cannot upgrade?
If upgrading is not possible, configure request limits or filter JSON payloads to reduce excessive parameter submissions as a temporary workaround for CVE-2020-27718.