CVE-2020-5868: OS Command Injection
Published Apr 24, 2020
·Updated
In BIG-IQ 6.0.0-7.0.0, a remote access vulnerability has been discovered that may allow a remote user to execute shell commands on affected systems using HTTP requests to the BIG-IQ user interface.
Affected Software
2 affected components
F5 BIG-IQ Centralized Management>=6.0.0<=6.1.0
F5 BIG-IQ Centralized Management=7.0.0
Event History
Apr 24, 2020
CVE Published
via MITRE·12:54 PM
Data Sourced
via MITRE·12:54 PM
Description
Frequently Asked Questions
1
What is CVE-2020-5868?
CVE-2020-5868 is a remote access vulnerability in BIG-IQ 6.0.0-7.0.0.
2
How does CVE-2020-5868 exploit work?
CVE-2020-5868 allows a remote user to execute shell commands on affected systems using HTTP requests to the BIG-IQ user interface.
3
What software versions are affected by CVE-2020-5868?
CVE-2020-5868 affects F5 BIG-IQ Centralized Management versions 6.0.0-6.1.0 and version 7.0.0.
4
What is the severity of CVE-2020-5868?
CVE-2020-5868 has a severity rating of 9.8 (Critical).
5
How can I fix CVE-2020-5868?
To fix CVE-2020-5868, upgrade to a non-vulnerable version of BIG-IQ Centralized Management.