CVE-2020-5886: Weak Encryption
On versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, and 12.1.0-12.1.5.1, BIG-IP systems setup for connection mirroring in a High Availability (HA) pair transfers sensitive cryptographic objects over an insecure communications channel. This is a control plane issue which is exposed only on the network used for connection mirroring.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-5886?
CVE-2020-5886 has been classified as a medium severity vulnerability due to the risk of sensitive information exposure.
How do I fix CVE-2020-5886?
To mitigate CVE-2020-5886, upgrade affected BIG-IP systems to the latest patched versions, specifically beyond version 15.1.0.1.
What systems are affected by CVE-2020-5886?
CVE-2020-5886 affects F5 BIG-IP systems, specifically versions 12.1.0 to 12.1.5.1, 13.1.0 to 13.1.3.3, 14.1.0 to 14.1.2.3, and 15.0.0 to 15.1.0.1.
What impact does CVE-2020-5886 have on my system?
CVE-2020-5886 could allow an attacker to intercept sensitive cryptographic objects due to insecure communication channels in connection mirroring.
Is CVE-2020-5886 a remote code execution vulnerability?
No, CVE-2020-5886 is not a remote code execution vulnerability; it primarily concerns the insecure transmission of sensitive data.