CVE-2020-5862
published 2020-03-27CVE-2020-5862: On BIG-IP 15.1.0-15.1.0.1, 15.0.0-15.0.1.1, and 14.1.0-14.1.2.2, under certain conditions, TMM may crash or stop processing new traffic with the DPDK/ENA…
PriorityP335high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.07%
61.0th percentile
On BIG-IP 15.1.0-15.1.0.1, 15.0.0-15.0.1.1, and 14.1.0-14.1.2.2, under certain conditions, TMM may crash or stop processing new traffic with the DPDK/ENA driver on AWS systems while sending traffic. This issue does not affect any other platforms, hardware or virtual, or any other cloud provider since the affected driver is specific to AWS.
Affected
57 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip_aam | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | 14.1.0 – 14.1.2.2 | — |
| f5 | big-ip_access_policy_manager | 15.0.0 – 15.0.1.1 | — |
| f5 | big-ip_access_policy_manager | 15.1.0 – 15.1.0.1 | — |
| f5 | big-ip_access_policy_manager | >= 15.1.0.4 < 15.1.3.1 | 15.1.3.1 |
| f5 | big-ip_advanced_firewall_manager | 14.1.0 – 14.1.2 | — |
| f5 | big-ip_advanced_firewall_manager | 15.0.0 – 15.0.1.1 | — |
| f5 | big-ip_advanced_firewall_manager | 15.1.0 – 15.1.0.1 | — |
| f5 | big-ip_advanced_firewall_manager | >= 15.1.0.4 < 15.1.3.1 | 15.1.3.1 |
| f5 | big-ip_advanced_waf | — | — |
| f5 | big-ip_advanced_web_application_firewall | >= 15.1.0.4 < 15.1.3.1 | 15.1.3.1 |
| f5 | big-ip_afm | — | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | 14.1.0 – 14.1.2 | — |
| f5 | big-ip_analytics | 15.0.0 – 15.0.1.1 | — |
| f5 | big-ip_analytics | 15.1.0 – 15.1.0.1 | — |
| f5 | big-ip_analytics | >= 15.1.0.4 < 15.1.3.1 | 15.1.3.1 |
| f5 | big-ip_apm | — | — |
| f5 | big-ip_application_acceleration_manager | 14.1.0 – 14.1.2 | — |
| f5 | big-ip_application_acceleration_manager | 15.0.0 – 15.0.1.1 | — |
| f5 | big-ip_application_acceleration_manager | 15.1.0 – 15.1.0.1 | — |
| f5 | big-ip_application_acceleration_manager | >= 15.1.0.4 < 15.1.3.1 | 15.1.3.1 |
| f5 | big-ip_application_security_manager | 14.1.0 – 14.1.2 | — |
| f5 | big-ip_application_security_manager | 15.0.0 – 15.0.1.1 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xwrf-mmfx-x4vx: On BIG-IP versions 15
ghsa_unreviewed·2022-05-24·CVSS 7.5
CVE-2021-23051 [HIGH] GHSA-xwrf-mmfx-x4vx: On BIG-IP versions 15
On BIG-IP versions 15.1.0.4 through 15.1.3, when the Data Plane Development Kit (DPDK)/Elastic Network Adapter (ENA) driver is used with BIG-IP on Amazon Web Services (AWS) systems, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. This is due to an incomplete fix for CVE-2020-5862. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
GHSA
GHSA-85v3-g58g-j776: On BIG-IP 15
ghsa_unreviewed·2022-05-24
CVE-2020-5862 [MEDIUM] CWE-20 GHSA-85v3-g58g-j776: On BIG-IP 15
On BIG-IP 15.1.0-15.1.0.1, 15.0.0-15.0.1.1, and 14.1.0-14.1.2.2, under certain conditions, TMM may crash or stop processing new traffic with the DPDK/ENA driver on AWS systems while sending traffic. This issue does not affect any other platforms, hardware or virtual, or any other cloud provider since the affected driver is specific to AWS.
F5
CVE-2021-23051: On BIG-IP versions 15
vendor_f5·2021-09-14·CVSS 7.5
CVE-2021-23051 [HIGH] CWE-20 CVE-2021-23051: On BIG-IP versions 15
CVE-2021-23051: On BIG-IP versions 15
On BIG-IP versions 15.1.0.4 through 15.1.3, when the Data Plane Development Kit (DPDK)/Elastic Network Adapter (ENA) driver is used with BIG-IP on Amazon Web Services (AWS) systems, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. This is due to an incomplete fix for CVE-2020-5862. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Products: BIG-IP AAM, BIG-IP AFM, BIG-IP APM, BIG-IP ASM, BIG-IP Advanced WAF, BIG-IP Analytics, BIG-IP DNS, BIG-IP FPS, BIG-IP GTM, BIG-IP LTM, BIG-IP Link Controller
Affected Versions: 15.1.0.4 - 15.1.3.1
F5 Advisory Articles: K01153535
F5 References: https://support.f5.com/csp/article/K01153535
F5
CVE-2020-5862: On BIG-IP 15
vendor_f5·2020-03-27·CVSS 7.5
CVE-2020-5862 [HIGH] CVE-2020-5862: On BIG-IP 15
CVE-2020-5862: On BIG-IP 15
On BIG-IP 15.1.0-15.1.0.1, 15.0.0-15.0.1.1, and 14.1.0-14.1.2.2, under certain conditions, TMM may crash or stop processing new traffic with the DPDK/ENA driver on AWS systems while sending traffic. This issue does not affect any other platforms, hardware or virtual, or any other cloud provider since the affected driver is specific to AWS.
Affected Products: BIG-IP AAM, BIG-IP AFM, BIG-IP APM, BIG-IP ASM, BIG-IP Analytics, BIG-IP DNS, BIG-IP FPS, BIG-IP GTM, BIG-IP LTM, BIG-IP Link Controller, BIG-IP PEM
Affected Versions: 14.1.0 - 14.1.2; 14.1.0 - 14.1.2.2; 15.0.0 - 15.0.1.1; 15.1.0 - 15.1.0.1
F5 Advisory Articles: K01054113
F5 References: https://support.f5.com/csp/article/K01054113
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-03-27
Published