CVE-2020-5856: High severity F5 BIG-IP Access Policy Manager vulnerability
On BIG-IP 15.0.0-15.0.1.1 and 14.1.0-14.1.2.2, while processing specifically crafted traffic using the default 'xnet' driver, Virtual Edition instances hosted in Amazon Web Services (AWS) may experience a TMM restart.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-5856?
CVE-2020-5856 is classified as a critical vulnerability due to its potential to cause a TMM restart in affected F5 BIG-IP instances.
How do I fix CVE-2020-5856?
To mitigate CVE-2020-5856, upgrade your F5 BIG-IP software to a version higher than 15.0.1.1 or 14.1.2.2.
What products are affected by CVE-2020-5856?
CVE-2020-5856 affects various versions of F5 BIG-IP Access Policy Manager, Advanced Firewall Manager, Analytics, Application Security Manager and others between 14.1.0 and 15.0.1.
How does CVE-2020-5856 impact AWS environments?
In AWS environments, CVE-2020-5856 can cause Virtual Edition instances to experience unexpected TMM restarts when processing malicious traffic.
What is TMM in the context of CVE-2020-5856?
TMM stands for Traffic Management Microkernel, which is responsible for processing traffic in F5 BIG-IP devices and can be restarted due to this vulnerability.