CVE-2020-5892: Medium severity f5 access policy manager vulnerability
In versions 7.1.5-7.1.8, the BIG-IP Edge Client components in BIG-IP APM, Edge Gateway, and FirePass legacy allow attackers to obtain the full session ID from process memory.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-5892?
CVE-2020-5892 is a vulnerability in the BIG-IP Edge Client components in BIG-IP APM, Edge Gateway, and FirePass legacy versions 7.1.5-7.1.8 that allows attackers to obtain the full session ID from process memory.
Which software versions are affected by CVE-2020-5892?
The affected software versions are F5 Big-ip Access Policy Manager versions 11.6.1-11.6.5, 12.1.0-12.1.5, 13.0.0-13.1.3, 14.0.0-14.1.2, 15.0.0-15.1.0, and F5 Big-ip Edge Gateway versions 11.6.1-11.6.5, 12.1.0-12.1.5, 13.0.0-13.1.3, 14.0.0-14.1.2, 15.0.0-15.1.0.
What is the severity of CVE-2020-5892?
CVE-2020-5892 has a severity value of 6.7, which is considered medium.
How can I fix CVE-2020-5892?
To fix CVE-2020-5892, F5 recommends upgrading to a fixed software version or applying the recommended mitigations provided in the F5 security advisory.
Where can I find more information about CVE-2020-5892?
You can find more information about CVE-2020-5892 in the F5 security advisory at the following link: [F5 Security Advisory](https://support.f5.com/csp/article/K15838353).