CVE-2020-5855
published 2020-02-06CVE-2020-5855: When the Windows Logon Integration feature is configured for all versions of BIG-IP Edge Client for Windows, unauthorized users who have physical access to an…
PriorityP417medium4.3CVSS 3.1
AVPACLPRNUINSUCLILAL
EPSS
0.33%
25.0th percentile
When the Windows Logon Integration feature is configured for all versions of BIG-IP Edge Client for Windows, unauthorized users who have physical access to an authorized user's machine can get shell access under unprivileged user.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip_access_policy_manager | 11.5.2 – 11.6.5 | — |
| f5 | big-ip_access_policy_manager | 12.1.0 – 12.1.5 | — |
| f5 | big-ip_access_policy_manager | 13.1.0 – 13.1.3 | — |
| f5 | big-ip_access_policy_manager | 14.1.0 – 14.1.2 | — |
| f5 | big-ip_access_policy_manager | 15.0.0 – 15.1.0 | — |
| f5 | big-ip_access_policy_manager_client | — | — |
| f5 | big-ip_access_policy_manager_client | 7.1.5 – 7.1.8 | — |
| f5 | big-ip_apm | — | — |
| f5 | edge_client_for_windows | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
F5
CVE-2020-5855: When the Windows Logon Integration feature is configured for all versions of BIG-IP Edge Client for Windows, unauthor...
vendor_f5·2020-02-06·CVSS 4.3
CVE-2020-5855 [MEDIUM] CVE-2020-5855: When the Windows Logon Integration feature is configured for all versions of BIG-IP Edge Client for Windows, unauthor...
CVE-2020-5855: When the Windows Logon Integration feature is configured for all versions of BIG-IP Edge Client for Windows, unauthor...
When the Windows Logon Integration feature is configured for all versions of BIG-IP Edge Client for Windows, unauthorized users who have physical access to an authorized user's machine can get shell access under unprivileged user.
Affected Products: BIG-IP APM, Big-Ip Access Policy Manager Client
Affected Versions: 11.5.2 - 11.6.5; 12.1.0 - 12.1.5; 13.1.0 - 13.1.3; 14.1.0 - 14.1.2; 15.0.0 - 15.1.0; 7.1.5 - 7.1.8
F5 Advisory Articles: K55102004
F5 References: https://support.f5.com/csp/article/K55102004
GHSA
GHSA-pr8j-wgf3-mgrx: When the Windows Logon Integration feature is configured for all versions of BIG-IP Edge Client for Windows, unauthorized users who have physical acce
ghsa_unreviewed·2022-05-24
CVE-2020-5855 [MEDIUM] CWE-863 GHSA-pr8j-wgf3-mgrx: When the Windows Logon Integration feature is configured for all versions of BIG-IP Edge Client for Windows, unauthorized users who have physical acce
When the Windows Logon Integration feature is configured for all versions of BIG-IP Edge Client for Windows, unauthorized users who have physical access to an authorized user's machine can get shell access under unprivileged user.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-02-06
Published