CVE-2020-5920: SQL Injection
In versions 15.0.0-15.1.0.5, 14.1.0-14.1.2.7, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, a vulnerability in the BIG-IP AFM Configuration utility may allow any authenticated BIG-IP user to perform a read-only blind SQL injection attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-5920?
CVE-2020-5920 is rated as a medium severity vulnerability.
How do I fix CVE-2020-5920?
To fix CVE-2020-5920, update your F5 BIG-IP Advanced Firewall Manager to a version above 15.1.0.5, 14.1.2.7, 13.1.3.4, 12.1.5.1, or 11.6.5.1.
Who is affected by CVE-2020-5920?
Any authenticated user of the affected versions of F5 BIG-IP Advanced Firewall Manager can potentially exploit CVE-2020-5920.
What type of attack can be executed through CVE-2020-5920?
CVE-2020-5920 allows authenticated users to perform a read-only blind SQL injection attack.
Which versions of F5 BIG-IP Advanced Firewall Manager are vulnerable to CVE-2020-5920?
Versions 15.0.0-15.1.0.5, 14.1.0-14.1.2.7, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1 are vulnerable to CVE-2020-5920.