CVE-2020-5885: Weak Encryption
On versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, and 12.1.0-12.1.5.1, BIG-IP systems set up for connection mirroring in a high availability (HA) pair transfer sensitive cryptographic objects over an insecure communications channel. This is a control plane issue which is exposed only on the network used for connection mirroring.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-5885?
CVE-2020-5885 is rated as a critical severity vulnerability due to its potential impact on sensitive cryptographic object transmission.
How do I fix CVE-2020-5885?
To fix CVE-2020-5885, upgrade your F5 BIG-IP systems to a version that is not affected, such as version 15.1.0.2 or later.
What systems are affected by CVE-2020-5885?
CVE-2020-5885 affects F5 BIG-IP Access Policy Manager, Advanced Firewall Manager, and other related components in versions 12.1.0 to 15.1.0.1.
What type of vulnerability is CVE-2020-5885?
CVE-2020-5885 is a control plane vulnerability that exposes sensitive data over an insecure communications channel.
Is CVE-2020-5885 specific to high availability configurations?
Yes, CVE-2020-5885 specifically impacts F5 BIG-IP systems configured for connection mirroring in high availability pairs.