CVE-2025-20027: Input Validation
Improper input validation in the UEFI WheaERST module for some Intel(R) reference platforms may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20027?
CVE-2025-20027 has a high severity rating due to its potential to allow escalation of privileges in affected systems.
How do I fix CVE-2025-20027?
To mitigate CVE-2025-20027, ensure that your F5 BIG-IP or F5OS software is updated to a patched version as recommended by the vendor.
What systems are impacted by CVE-2025-20027?
CVE-2025-20027 affects specific versions of F5 BIG-IP and F5OS-A and F5OS-C across various release ranges.
What kind of attacks can exploit CVE-2025-20027?
CVE-2025-20027 can be exploited through a local attack by adversaries with privileged access utilizing complex methods.
Who should be concerned about CVE-2025-20027?
Organizations using affected versions of F5 BIG-IP and F5OS products should be concerned about CVE-2025-20027 and take immediate action to secure their systems.