CVE-2020-5875: High severity f5 access policy manager vulnerability
On BIG-IP 15.0.0-15.0.1 and 14.1.0-14.1.2.3, under certain conditions, the Traffic Management Microkernel (TMM) may generate a core file and restart while processing SSL traffic with an HTTP/2 full proxy.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-5875?
CVE-2020-5875 has been rated as a high severity vulnerability due to its potential impact on system availability.
How do I fix CVE-2020-5875?
To remedy CVE-2020-5875, you should upgrade your F5 BIG-IP software to versions 15.0.1 or 14.1.2.4 and above.
Which F5 BIG-IP versions are affected by CVE-2020-5875?
CVE-2020-5875 affects F5 BIG-IP versions 15.0.0 to 15.0.1 and 14.1.0 to 14.1.2.3.
What are the consequences of not addressing CVE-2020-5875?
Failing to address CVE-2020-5875 may lead to unexpected system restarts and potential service downtime while processing SSL traffic.
Is CVE-2020-5875 related to SSL traffic?
Yes, CVE-2020-5875 specifically concerns the handling of SSL traffic by the Traffic Management Microkernel in F5 BIG-IP systems.