CVE-2020-5874: High severity f5 access policy manager vulnerability
On BIG-IP APM 15.0.0-15.0.1.2, 14.1.0-14.1.2.3, and 14.0.0-14.0.1, in certain circumstances, an attacker sending specifically crafted requests to a BIG-IP APM virtual server may cause a disruption of service provided by the Traffic Management Microkernel(TMM).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-5874?
CVE-2020-5874 is considered a medium severity vulnerability that may lead to service disruption.
How do I fix CVE-2020-5874?
To fix CVE-2020-5874, upgrade to a patched version of F5 BIG-IP APM that is not affected by this vulnerability.
What products are affected by CVE-2020-5874?
CVE-2020-5874 affects F5 BIG-IP Access Policy Manager versions 14.0.0 to 14.0.1, 14.1.0 to 14.1.2.3, and 15.0.0 to 15.0.1.2.
What type of attack is CVE-2020-5874 associated with?
CVE-2020-5874 is associated with an attacker sending specifically crafted requests that disrupt service on the Traffic Management Microkernel.
What is the impact of exploiting CVE-2020-5874?
Exploitation of CVE-2020-5874 can result in a denial-of-service condition affecting the functionality of BIG-IP APM.