CVE-2020-5926: High severity f5 access policy manager vulnerability
In BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, and 14.1.0-14.1.2.6, a BIG-IP virtual server with a Session Initiation Protocol (SIP) ALG profile, parsing SIP messages that contain a multi-part MIME payload with certain boundary strings can cause TMM to free memory to the wrong cache.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-5926?
CVE-2020-5926 is classified as a high severity vulnerability.
How do I fix CVE-2020-5926?
To remediate CVE-2020-5926, upgrade to the versions provided by F5 that are not vulnerable.
What software is affected by CVE-2020-5926?
CVE-2020-5926 affects F5 BIG-IP Access Policy Manager, Advanced Firewall Manager, Analytics, Application Acceleration Manager, Application Security Manager, Domain Name System, Fraud Protection Service, Global Traffic Manager, Link Controller, Local Traffic Manager, and Policy Enforcement Manager.
What is the impact of CVE-2020-5926 on system performance?
CVE-2020-5926 can cause the Traffic Management Microkernel (TMM) to free memory incorrectly, potentially leading to performance degradation.
What types of payloads are involved in CVE-2020-5926?
CVE-2020-5926 is associated with SIP messages that contain a multi-part MIME payload with specific boundary strings.