CVE-2020-5851: Medium severity F5 Big-ip Local Traffic Manager vulnerability
On impacted versions and platforms the Trusted Platform Module (TPM) system integrity check cannot detect modifications to specific system components. This issue only impacts specific engineering hotfixes and platforms. NOTE: This vulnerability does not affect any of the BIG-IP major, minor or maintenance releases you obtained from downloads.f5.com. The affected Engineering Hotfix builds are as follows: Hotfix-BIGIP-14.1.0.2.0.45.4-ENG Hotfix-BIGIP-14.1.0.2.0.62.4-ENG
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
F5 BIG-IP engineering hotfix (Hotfix-BIGIP-14.1.0.2.0.*-ENG)to a version that resolves this vulnerability.Fixed in Hotfix-BIGIP-14.1.0.2.0.45.4-ENG - Upgrade
Upgrade
F5 BIG-IP engineering hotfix (Hotfix-BIGIP-14.1.0.2.0.*-ENG)to a version that resolves this vulnerability.Fixed in Hotfix-BIGIP-14.1.0.2.0.62.4-ENG
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-5851.
What is the severity of CVE-2020-5851?
The severity of CVE-2020-5851 is medium.
What systems are affected by CVE-2020-5851?
CVE-2020-5851 affects F5 Big-ip Local Traffic Manager, F5 Big-ip Advanced Firewall Manager, F5 Big-ip Application Acceleration Manager, F5 BIG-IP Analytics, F5 Big-ip Access Policy Manager, F5 BIG-IP Application Security Manager, F5 Big-ip Edge Gateway, F5 Big-ip Fraud Protection Service, F5 Big-ip Global Traffic Manager, F5 Big-ip Link Controller, F5 Big-ip Policy Enforcement Manager, F5 Big-ip Webaccelerator, and F5 Big-ip Domain Name System on specific versions.
What is the impact of CVE-2020-5851?
CVE-2020-5851 allows modifications to specific system components that cannot be detected by the Trusted Platform Module (TPM) system integrity check.
How can I fix CVE-2020-5851?
To fix CVE-2020-5851, apply the necessary engineering hotfixes provided by F5 Networks.