CVE-2020-5888: High severity riverbed steelapp traffic manager vulnerability
On versions 15.1.0-15.1.0.1, 15.0.0-15.0.1.2, and 14.1.0-14.1.2.3, BIG-IP Virtual Edition (VE) may expose a mechanism for adjacent network (layer 2) attackers to access local daemons and bypass port lockdown settings.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-5888?
CVE-2020-5888 has been assigned a medium severity rating due to the potential for adjacent network attackers to exploit local daemons.
How do I fix CVE-2020-5888?
To mitigate CVE-2020-5888, users should upgrade their F5 BIG-IP software to the latest patched version outside the affected ranges.
Which versions are affected by CVE-2020-5888?
CVE-2020-5888 affects F5 BIG-IP versions 15.1.0-15.1.0.1, 15.0.0-15.0.1.2, and 14.1.0-14.1.2.3.
Who is at risk from CVE-2020-5888?
Organizations using the specified versions of F5 BIG-IP products in their network environments are at risk from CVE-2020-5888.
Is there any workaround for CVE-2020-5888?
There are no official workarounds for CVE-2020-5888, so the recommended approach is to apply the necessary software updates.