CVE-2020-5871: High severity f5 access policy manager vulnerability
On BIG-IP 14.1.0-14.1.2.3, undisclosed requests can lead to a denial of service (DoS) when sent to BIG-IP HTTP/2 virtual servers. The problem can occur when ciphers, which have been blacklisted by the HTTP/2 RFC, are used on backend servers. This is a data-plane issue. There is no control-plane exposure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-5871?
CVE-2020-5871 is a denial-of-service vulnerability that can impact the availability of BIG-IP HTTP/2 virtual servers.
How do I mitigate CVE-2020-5871?
To mitigate CVE-2020-5871, you should ensure that backend servers do not use ciphers that are blacklisted by the HTTP/2 RFC.
Which versions of F5 BIG-IP are affected by CVE-2020-5871?
CVE-2020-5871 affects F5 BIG-IP versions 14.1.0 through 14.1.2.3.
What type of issue is CVE-2020-5871 classified as?
CVE-2020-5871 is classified as a data-plane issue.
Is there a patch available for CVE-2020-5871?
Users should refer to F5's official channels for information on patches related to CVE-2020-5871.