CVE-2020-5935: Medium severity f5 access policy manager vulnerability
On BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, FPS, GTM, Link Controller, PEM) versions 15.1.0-15.1.0.5, 14.1.0-14.1.2.3, and 13.1.0-13.1.3.3, when handling MQTT traffic through a BIG-IP virtual server associated with an MQTT profile and an iRule performing manipulations on that traffic, TMM may produce a core file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-5935?
CVE-2020-5935 is rated as a critical vulnerability affecting specific versions of F5 BIG-IP products.
How do I fix CVE-2020-5935?
To fix CVE-2020-5935, upgrade to version 15.1.1, 14.1.2.4, or 13.1.3.4 of the affected F5 BIG-IP products.
Which versions are affected by CVE-2020-5935?
CVE-2020-5935 affects F5 BIG-IP versions 15.1.0-15.1.0.5, 14.1.0-14.1.2.3, and 13.1.0-13.1.3.3.
What type of vulnerability is CVE-2020-5935?
CVE-2020-5935 is a vulnerability that occurs when handling MQTT traffic through specific configurations in F5 BIG-IP.
Is there a workaround for CVE-2020-5935?
While upgrading is the best solution, temporarily disabling MQTT traffic could serve as a workaround for CVE-2020-5935.