CVE-2020-5869: Critical severity f5 big-ip and big-iq centralized management vulnerability
Published Apr 24, 2020
·Updated
In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization is not secure by TLS and may allow on-path attackers to read / modify confidential data in transit.
Affected Software
3 affected components
F5 BIG-IQ Centralized Management>=5.2.0<=5.4.0
F5 BIG-IQ Centralized Management>=6.0.0<=6.1.0
F5 BIG-IQ Centralized Management>=7.0.0<7.1.0
Event History
Apr 24, 2020
CVE Published
via MITRE·01:05 PM
Data Sourced
via MITRE·01:05 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2020-5869.
2
What is the severity of CVE-2020-5869?
The severity of CVE-2020-5869 is critical with a CVSS score of 9.1.
3
Which software versions are affected by CVE-2020-5869?
The affected software versions include BIG-IQ Centralized Management versions 5.2.0 to 7.0.0 (inclusive).
4
How does CVE-2020-5869 exploit work?
CVE-2020-5869 allows on-path attackers to read/modify confidential data in transit by exploiting the lack of secure TLS in high availability (HA) synchronization in BIG-IQ Centralized Management.
5
Is there a fix available for CVE-2020-5869?
Yes, F5 has released a fix for CVE-2020-5869. It is recommended to update to a patched version of BIG-IQ Centralized Management.