CVE-2020-5898
published 2020-05-12CVE-2020-5898: In versions 7.1.5-7.1.9, BIG-IP Edge Client Windows Stonewall driver does not sanitize the pointer received from the userland. A local user on the Windows…
PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
17.5th percentile
In versions 7.1.5-7.1.9, BIG-IP Edge Client Windows Stonewall driver does not sanitize the pointer received from the userland. A local user on the Windows client system can send crafted DeviceIoControl requests to \\.\urvpndrv device causing the Windows kernel to crash.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip_access_policy_manager | 11.6.1 – 11.6.5.1 | — |
| f5 | big-ip_access_policy_manager | 12.1.0 – 12.1.5.1 | — |
| f5 | big-ip_access_policy_manager | 13.1.0 – 13.1.3.3 | — |
| f5 | big-ip_access_policy_manager | 14.1.0 – 14.1.2.5 | — |
| f5 | big-ip_access_policy_manager | 15.0.0 – 15.1.0.3 | — |
| f5 | big-ip_access_policy_manager_client | — | — |
| f5 | big-ip_access_policy_manager_client | 7.1.5 – 7.1.9 | — |
| f5 | big-ip_apm | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
F5
CVE-2020-5898: In versions 7
vendor_f5·2020-05-12·CVSS 5.5
CVE-2020-5898 [MEDIUM] CVE-2020-5898: In versions 7
CVE-2020-5898: In versions 7
In versions 7.1.5-7.1.9, BIG-IP Edge Client Windows Stonewall driver does not sanitize the pointer received from the userland. A local user on the Windows client system can send crafted DeviceIoControl requests to \\.\urvpndrv device causing the Windows kernel to crash.
Affected Products: BIG-IP APM, Big-Ip Access Policy Manager Client
Affected Versions: 11.6.1 - 11.6.5.1; 12.1.0 - 12.1.5.1; 13.1.0 - 13.1.3.3; 14.1.0 - 14.1.2.5; 15.0.0 - 15.1.0.3; 7.1.5 - 7.1.9
F5 Advisory Articles: K69154630
F5 References: https://support.f5.com/csp/article/K69154630
GHSA
GHSA-jp6c-5v5f-m9j9: In versions 7
ghsa_unreviewed·2022-05-24
CVE-2020-5898 [MEDIUM] GHSA-jp6c-5v5f-m9j9: In versions 7
In versions 7.1.5-7.1.9, BIG-IP Edge Client Windows Stonewall driver does not sanitize the pointer received from the userland. A local user on the Windows client system can send crafted DeviceIoControl requests to \\.\urvpndrv device causing the Windows kernel to crash.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-05-12
Published