CVE-2020-5879: High severity f5 application security manager vulnerability
Published Apr 30, 2020
·Updated
On BIG-IP ASM 11.6.1-11.6.5.1, under certain configurations, the BIG-IP system sends data plane traffic to back-end servers unencrypted, even when a Server SSL profile is applied.
Affected Software
1 affected component
F5 BIG-IP Application Security Manager>=11.6.1<=11.6.5.1
Event History
Apr 30, 2020
CVE Published
via MITRE·08:46 PM
Data Sourced
via MITRE·08:46 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-5879?
CVE-2020-5879 is rated as a medium severity vulnerability.
2
How do I fix CVE-2020-5879?
To fix CVE-2020-5879, you should upgrade to a patched version of the BIG-IP ASM that is higher than 11.6.5.1.
3
What versions of BIG-IP ASM are affected by CVE-2020-5879?
CVE-2020-5879 affects F5 BIG-IP Application Security Manager versions 11.6.1 through 11.6.5.1.
4
What impact does CVE-2020-5879 have?
CVE-2020-5879 allows unencrypted data plane traffic to be sent to back-end servers under certain configurations.
5
Is there a workaround for CVE-2020-5879?
There are no official workarounds for CVE-2020-5879; upgrading to a secure version is recommended.