CVE-2020-5921: High severity f5 access policy manager vulnerability
in BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.6, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2, Syn flood causes large number of MCPD context messages destined to secondary blades consuming memory leading to MCPD failure. This issue affects only VIPRION hosts with two or more blades installed. Single-blade VIPRION hosts are not affected.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-5921?
CVE-2020-5921 is rated as a high severity vulnerability due to its potential to consume significant memory resources on affected systems.
How do I fix CVE-2020-5921?
To mitigate CVE-2020-5921, upgrade to the latest patched version of the F5 BIG-IP software that is not affected by this vulnerability.
Which F5 BIG-IP versions are affected by CVE-2020-5921?
CVE-2020-5921 affects F5 BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.6, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2.
What impact does CVE-2020-5921 have on affected systems?
The impact of CVE-2020-5921 includes a potential Denial of Service due to memory consumption from excessive MCPD context messages.
Who is affected by CVE-2020-5921?
Only users operating VIPRION hosts with two or more blades are affected by CVE-2020-5921.