CVE-2020-27725: Medium severity f5 big-ip vulnerability
In version 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2 of BIG-IP DNS, GTM, and Link Controller, zxfrd leaks memory when listing DNS zones. Zones can be listed via TMSH, iControl or SNMP; only users with access to those services can trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-27725?
CVE-2020-27725 has been classified as a Medium severity vulnerability.
How do I fix CVE-2020-27725?
To remediate CVE-2020-27725, you should upgrade your F5 BIG-IP DNS, GTM, or Link Controller to a version that is not affected by this vulnerability.
What versions are affected by CVE-2020-27725?
CVE-2020-27725 affects F5 BIG-IP versions ranging from 11.6.1 to 15.1.0.5, including several intermediate versions.
Can CVE-2020-27725 be exploited remotely?
CVE-2020-27725 requires local access via TMSH, iControl, or SNMP, so it cannot be exploited remotely.
What type of data is leaked in CVE-2020-27725?
CVE-2020-27725 causes a memory leak when listing DNS zones, potentially exposing sensitive data.