CVE-2020-5924: Medium severity f5 access policy manager vulnerability
Published Aug 26, 2020
·Updated
In BIG-IP APM versions 12.1.0-12.1.5.1 and 11.6.1-11.6.5.2, RADIUS authentication leaks memory when the username for authentication is not set.
Affected Software
2 affected components
F5 BIG-IP Access Policy Manager>=11.6.1<=11.6.5
F5 BIG-IP Access Policy Manager>=12.1.0<12.1.5.2
Event History
Aug 26, 2020
CVE Published
via MITRE·02:38 PM
Data Sourced
via MITRE·02:38 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-5924?
CVE-2020-5924 is rated as a medium severity vulnerability.
2
How do I fix CVE-2020-5924?
To fix CVE-2020-5924, upgrade F5 BIG-IP APM to a version that is not vulnerable, such as versions 12.1.5.2 or later for the affected 12.x series.
3
What versions are affected by CVE-2020-5924?
CVE-2020-5924 affects BIG-IP APM versions 12.1.0 to 12.1.5.1 and 11.6.1 to 11.6.5.2.
4
What is the impact of CVE-2020-5924?
The impact of CVE-2020-5924 includes potential memory leaks during RADIUS authentication when the username is not set.
5
Who is impacted by CVE-2020-5924?
Organizations using the specified vulnerable versions of F5 BIG-IP APM for RADIUS authentication are impacted by CVE-2020-5924.