First published: Wed Aug 26 2020(Updated: )
In BIG-IP ASM versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, undisclosed server cookie scenario may cause BD to restart under some circumstances.
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 BIG-IP Application Security Manager | >=11.5.2<11.6.5.2 | |
F5 BIG-IP Application Security Manager | >=12.1.0<12.1.5.2 | |
F5 BIG-IP Application Security Manager | >=13.1.0<13.1.3.4 | |
F5 BIG-IP Application Security Manager | >=14.1.0<14.1.2.5 | |
F5 BIG-IP Application Security Manager | >=15.0.0<15.0.1.4 | |
F5 BIG-IP Application Security Manager | >=15.1.0<15.1.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-5914 is a vulnerability in BIG-IP ASM (Application Security Manager) versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1 that may cause the BD (discard-based) to restart under certain circumstances.
CVE-2020-5914 has a severity rating of 7.5 (high).
If you are using BIG-IP ASM versions 11.5.2-11.6.5.1, 12.1.0-12.1.5.2, 13.1.0-13.1.3.4, 14.1.0-14.1.2.5, 15.0.0-15.0.1.4, or 15.1.0-15.1.0.5, then your version is affected by CVE-2020-5914.
To fix CVE-2020-5914, upgrade to a version of BIG-IP ASM that is not vulnerable (e.g., versions 11.6.5.2 or higher, 12.1.5.2 or higher, 13.1.3.4 or higher, 14.1.2.5 or higher, 15.0.1.4 or higher, or 15.1.0.5 or higher).
You can find more information about CVE-2020-5914 on the F5 Networks support website: https://support.f5.com/csp/article/K37466356