cbcvebase.
CVE-2020-5902
published 2020-07-01

CVE-2020-5902: In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulnerability in undisclosed pages.

Affected

99 ranges· showing 25
VendorProductVersion rangeFixed in
f5big-ip_aam
f5big-ip_access_policy_manager
f5big-ip_access_policy_manager>= 11.6.1 < 11.6.5.211.6.5.2
f5big-ip_access_policy_manager>= 12.1.0 < 12.1.5.212.1.5.2
f5big-ip_access_policy_manager>= 13.1.0 < 13.1.3.413.1.3.4
f5big-ip_access_policy_manager>= 14.1.0 < 14.1.2.614.1.2.6
f5big-ip_access_policy_manager15.0.0 – 15.0.1.4
f5big-ip_access_policy_manager>= 15.1.0 < 15.1.0.415.1.0.4
f5big-ip_advanced_firewall_manager>= 11.6.1 < 11.6.5.211.6.5.2
f5big-ip_advanced_firewall_manager>= 12.1.0 < 12.1.5.212.1.5.2
f5big-ip_advanced_firewall_manager>= 13.1.0 < 13.1.3.413.1.3.4
f5big-ip_advanced_firewall_manager>= 14.1.0 < 14.1.2.614.1.2.6
f5big-ip_advanced_firewall_manager>= 15.0.0 < 15.0.1.415.0.1.4
f5big-ip_advanced_firewall_manager>= 15.1.0 < 15.1.0.415.1.0.4
f5big-ip_advanced_waf
f5big-ip_advanced_web_application_firewall>= 11.6.1 < 11.6.5.211.6.5.2
f5big-ip_advanced_web_application_firewall>= 12.1.0 < 12.1.5.212.1.5.2
f5big-ip_advanced_web_application_firewall>= 13.1.0 < 13.1.3.413.1.3.4
f5big-ip_advanced_web_application_firewall>= 14.1.0 < 14.1.2.614.1.2.6
f5big-ip_advanced_web_application_firewall>= 15.0.0 < 15.0.1.415.0.1.4
f5big-ip_advanced_web_application_firewall>= 15.1.0 < 15.1.0.415.1.0.4
f5big-ip_afm
f5big-ip_analytics
f5big-ip_analytics>= 11.6.1 < 11.6.5.211.6.5.2
f5big-ip_analytics>= 12.1.0 < 12.1.5.212.1.5.2

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL