First published: Thu Dec 24 2020(Updated: )
In BIG-IP APM versions 15.0.0-15.0.1.3, 14.1.0-14.1.3, and 13.1.0-13.1.3.4, under certain conditions, the VDI plugin does not observe plugin flow-control protocol causing excessive resource consumption.
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 Big-ip Access Policy Manager | >=13.1.0<13.1.3.5 | |
F5 Big-ip Access Policy Manager | >=14.1.0<14.1.3.1 | |
F5 Big-ip Access Policy Manager | >=15.0.0<15.0.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27722 is rated as a medium severity vulnerability.
To mitigate CVE-2020-27722, upgrade to a fixed version of BIG-IP APM that is not vulnerable.
CVE-2020-27722 affects BIG-IP APM versions 15.0.0 through 15.0.1.3, 14.1.0 through 14.1.3, and 13.1.0 through 13.1.3.4.
CVE-2020-27722 represents a resource consumption issue due to a failure in plugin flow-control in the VDI plugin.
Currently, there are no known public exploits that actively target CVE-2020-27722.