First published: Thu Feb 06 2020(Updated: )
When the Windows Logon Integration feature is configured for all versions of BIG-IP Edge Client for Windows, unauthorized users who have physical access to an authorized user's machine can get shell access under unprivileged user.
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 Big-ip Access Policy Manager | >=11.5.2<=11.6.5 | |
F5 Big-ip Access Policy Manager | >=12.1.0<=12.1.5 | |
F5 Big-ip Access Policy Manager | >=13.1.0<=13.1.3 | |
F5 Big-ip Access Policy Manager | >=14.1.0<=14.1.2 | |
F5 Big-ip Access Policy Manager | >=15.0.0<=15.1.0 | |
F5 Big-ip Access Policy Manager Client | >=7.1.5<=7.1.8 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-5855 is a vulnerability that allows unauthorized users to get shell access on a machine running BIG-IP Edge Client for Windows.
CVE-2020-5855 has a severity level of 4.3, which is considered medium.
CVE-2020-5855 affects all versions of BIG-IP Access Policy Manager for Windows up to version 15.1.0 and BIG-IP Access Policy Manager Client for Windows up to version 7.1.8.
Unauthorized users with physical access to an authorized user's machine can exploit CVE-2020-5855 to gain shell access as an unprivileged user.
To fix CVE-2020-5855, it is recommended to update BIG-IP Access Policy Manager and BIG-IP Access Policy Manager Client to the latest patched versions provided by F5.