CVE-2020-27722: Medium severity f5 access policy manager vulnerability
Published Dec 24, 2020
·Updated
In BIG-IP APM versions 15.0.0-15.0.1.3, 14.1.0-14.1.3, and 13.1.0-13.1.3.4, under certain conditions, the VDI plugin does not observe plugin flow-control protocol causing excessive resource consumption.
Affected Software
3 affected components
F5 BIG-IP Access Policy Manager>=13.1.0<13.1.3.5
F5 BIG-IP Access Policy Manager>=14.1.0<14.1.3.1
F5 BIG-IP Access Policy Manager>=15.0.0<15.0.1.4
Event History
Dec 24, 2020
CVE Published
via MITRE·03:13 PM
Data Sourced
via MITRE·03:13 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-27722?
CVE-2020-27722 is rated as a medium severity vulnerability.
2
How do I fix CVE-2020-27722?
To mitigate CVE-2020-27722, upgrade to a fixed version of BIG-IP APM that is not vulnerable.
3
Which versions are affected by CVE-2020-27722?
CVE-2020-27722 affects BIG-IP APM versions 15.0.0 through 15.0.1.3, 14.1.0 through 14.1.3, and 13.1.0 through 13.1.3.4.
4
What type of issue does CVE-2020-27722 represent?
CVE-2020-27722 represents a resource consumption issue due to a failure in plugin flow-control in the VDI plugin.
5
Is there a known exploit for CVE-2020-27722?
Currently, there are no known public exploits that actively target CVE-2020-27722.