CVE-2020-5870: High severity f5 big-ip and big-iq centralized management vulnerability
Published Apr 24, 2020
·Updated
In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization mechanisms do not use any form of authentication for connecting to the peer.
Affected Software
3 affected components
F5 BIG-IQ Centralized Management>=5.2.0<=5.4.0
F5 BIG-IQ Centralized Management>=6.0.0<=6.1.0
F5 BIG-IQ Centralized Management>=7.0.0<7.1.0
Event History
Apr 24, 2020
CVE Published
via MITRE·01:17 PM
Data Sourced
via MITRE·01:17 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2020-5870.
2
What is the severity of CVE-2020-5870?
The severity of CVE-2020-5870 is high.
3
Which software versions are affected by CVE-2020-5870?
BIG-IQ Centralized Management versions 5.2.0 to 5.4.0, 6.0.0 to 6.1.0, and 7.0.0 to 7.1.0 are affected.
4
What is the description of CVE-2020-5870?
CVE-2020-5870 is a vulnerability in BIG-IQ Centralized Management where high availability (HA) synchronization mechanisms do not use any form of authentication for connecting to the peer.
5
How can I find more information about CVE-2020-5870?
More information about CVE-2020-5870 can be found at the following reference link: [link](https://support.f5.com/csp/article/K69422435).