CVE-2020-5948: XSS
On BIG-IP versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.2.7, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, undisclosed endpoints in iControl REST allow for a reflected XSS attack, which could lead to a complete compromise of the BIG-IP system if the victim user is granted the admin role.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-5948?
CVE-2020-5948 has been classified as a reflected XSS vulnerability that could lead to complete compromise of the BIG-IP system.
How do I fix CVE-2020-5948?
To fix CVE-2020-5948, you should upgrade your BIG-IP versions to the fixed releases provided by F5 in their security updates.
Which versions are affected by CVE-2020-5948?
CVE-2020-5948 affects BIG-IP versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.2.7, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2.
What types of attacks can CVE-2020-5948 enable?
CVE-2020-5948 enables reflected XSS attacks, which can allow attackers to execute scripts in the context of the user's session.
Is user interaction required to exploit CVE-2020-5948?
Yes, exploitation of CVE-2020-5948 typically requires that a user be tricked into clicking a malicious link.