CVE-2020-27728: High severity f5 big-ip advanced waf/asm vulnerability
On BIG-IP ASM & Advanced WAF versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.3, under certain conditions, Analytics, Visibility, and Reporting daemon (AVRD) may generate a core file and restart on the BIG-IP system when processing requests sent from mobile devices.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-27728?
CVE-2020-27728 has been assigned a severity rating that highlights significant impact on the performance and stability of the affected systems.
How do I fix CVE-2020-27728?
To fix CVE-2020-27728, you must upgrade to a non-vulnerable version of the F5 BIG-IP product, specifically after the indicated versions.
What systems are affected by CVE-2020-27728?
CVE-2020-27728 affects F5 BIG-IP ASM and Advanced WAF versions 14.1.0 to 14.1.3, 15.0.0 to 15.1.0, and 16.0.0 to 16.0.1.
What are the symptoms of CVE-2020-27728?
The symptoms of CVE-2020-27728 include unexpected core file generation and the AVRD daemon restarting on the BIG-IP system.
Is CVE-2020-27728 exploitable remotely?
CVE-2020-27728 can be exploited remotely under specific conditions when processing requests sent from mobile devices.