CVE-2020-5903
published 2020-07-01CVE-2020-5903: In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, a Cross-Site Scripting (XSS) vulnerability exists in an undisclosed page…
PriorityP429medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
2.23%
80.8th percentile
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, a Cross-Site Scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility.
Affected
56 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip_aam | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | 12.1.0 – 12.1.5 | — |
| f5 | big-ip_access_policy_manager | 13.1.0 – 13.1.3 | — |
| f5 | big-ip_access_policy_manager | 14.1.0 – 14.1.2 | — |
| f5 | big-ip_access_policy_manager | 15.0.0 – 15.1.0 | — |
| f5 | big-ip_advanced_firewall_manager | 12.1.0 – 12.1.5 | — |
| f5 | big-ip_advanced_firewall_manager | 13.1.0 – 13.1.3 | — |
| f5 | big-ip_advanced_firewall_manager | 14.1.0 – 14.1.2 | — |
| f5 | big-ip_advanced_firewall_manager | 15.0.0 – 15.1.0 | — |
| f5 | big-ip_afm | — | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | 12.1.0 – 12.1.5 | — |
| f5 | big-ip_analytics | 13.1.0 – 13.1.3 | — |
| f5 | big-ip_analytics | 14.1.0 – 14.1.2 | — |
| f5 | big-ip_analytics | 15.0.0 – 15.1.0 | — |
| f5 | big-ip_apm | — | — |
| f5 | big-ip_application_acceleration_manager | 12.1.0 – 12.1.5 | — |
| f5 | big-ip_application_acceleration_manager | 13.1.0 – 13.1.3 | — |
| f5 | big-ip_application_acceleration_manager | 14.1.0 – 14.1.2 | — |
| f5 | big-ip_application_acceleration_manager | 15.0.0 – 15.1.0 | — |
| f5 | big-ip_application_security_manager | 12.1.0 – 12.1.5 | — |
| f5 | big-ip_application_security_manager | 13.1.0 – 13.1.3 | — |
| f5 | big-ip_application_security_manager | 14.1.0 – 14.1.2 | — |
| f5 | big-ip_application_security_manager | 15.0.0 – 15.1.0 | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q6xc-mgx9-83rc: In BIG-IP versions 15
ghsa_unreviewed·2022-05-24
CVE-2020-5903 [MEDIUM] CWE-79 GHSA-q6xc-mgx9-83rc: In BIG-IP versions 15
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, a Cross-Site Scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility.
F5
CVE-2020-5903: In BIG-IP versions 15
vendor_f5·2020-07-01·CVSS 6.1
CVE-2020-5903 [MEDIUM] CWE-79 CVE-2020-5903: In BIG-IP versions 15
CVE-2020-5903: In BIG-IP versions 15
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, a Cross-Site Scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility.
Affected Products: BIG-IP AAM, BIG-IP AFM, BIG-IP APM, BIG-IP ASM, BIG-IP Analytics, BIG-IP DNS, BIG-IP FPS, BIG-IP GTM, BIG-IP LTM, BIG-IP Link Controller, BIG-IP PEM
Affected Versions: 12.1.0 - 12.1.5; 13.1.0 - 13.1.3; 14.1.0 - 14.1.2; 15.0.0 - 15.1.0
F5 Advisory Articles: K43638305
F5 References: https://support.f5.com/csp/article/K43638305
No detection rules found.
No public exploits indexed.
Trendmicro
This Week in Security News: 07/10/2020
blogs_trendmicro·2020-07-10·CVSS 8.8
[HIGH] This Week in Security News: 07/10/2020
Exploits & Vulnerabilities
## This Week in Security News: 07/10/2020
This week, read about how fifteen billion usernames and passwords for a range of internet services are currently for sale on underground forums.
By: Jon Clay 2020/07/10 Read time: ( words)
Save to Folio
Welcome to our weekly roundup, where we share what you need to know about the cybersecurity news and events that happened over the past few days. This week, read about how fifteen billion usernames and passwords for a range of internet services are currently for sale on underground forums. Also, learn about a new Mirai variant that exploits nine vulnerabilities, most notable of which is CVE-2020-10173. Read on:
Cloud Security is Simple, Absolutely Simple.
“Cloud security is simple, absolutely simple. Stop over compl
Trendmicro
This Week in Security News: 07/10/2020
blogs_trendmicro·2020-07-10·CVSS 8.8
[HIGH] This Week in Security News: 07/10/2020
Exploits y vulnerabilidades
## This Week in Security News: 07/10/2020
This week, read about how fifteen billion usernames and passwords for a range of internet services are currently for sale on underground forums.
By: Jon Clay Jul 10, 2020 Read time: ( words)
Save to Folio
Welcome to our weekly roundup, where we share what you need to know about the cybersecurity news and events that happened over the past few days. This week, read about how fifteen billion usernames and passwords for a range of internet services are currently for sale on underground forums. Also, learn about a new Mirai variant that exploits nine vulnerabilities, most notable of which is CVE-2020-10173. Read on:
Cloud Security is Simple, Absolutely Simple.
“Cloud security is simple, absolutely simple. Stop over co
Trendmicro
This Week in Security News: 07/10/2020
blogs_trendmicro·2020-07-10·CVSS 8.8
[HIGH] This Week in Security News: 07/10/2020
Exploits & Vulnerabilities
# This Week in Security News: 07/10/2020
This week, read about how fifteen billion usernames and passwords for a range of internet services are currently for sale on underground forums.
By: Jon Clay
2020/07/10
Read time: ( words)
Save to Folio
Welcome to our weekly roundup, where we share what you need to know about the cybersecurity news and events that happened over the past few days. This week, read about how fifteen billion usernames and passwords for a range of internet services are currently for sale on underground forums. Also, learn about a new Mirai variant that exploits nine vulnerabilities, most notable of which is CVE-2020-10173. Read on:
Cloud Security is Simple, Absolutely Simple.
“Cloud security is simple, absolutely simple. Stop over compl
Trendmicro
This Week in Security News: 07/10/2020
blogs_trendmicro·2020-07-10·CVSS 8.8
[HIGH] This Week in Security News: 07/10/2020
Exploits & Vulnerabilities
## This Week in Security News: 07/10/2020
This week, read about how fifteen billion usernames and passwords for a range of internet services are currently for sale on underground forums.
By: Jon Clay Jul 10, 2020 Read time: ( words)
Save to Folio
Welcome to our weekly roundup, where we share what you need to know about the cybersecurity news and events that happened over the past few days. This week, read about how fifteen billion usernames and passwords for a range of internet services are currently for sale on underground forums. Also, learn about a new Mirai variant that exploits nine vulnerabilities, most notable of which is CVE-2020-10173. Read on:
Cloud Security is Simple, Absolutely Simple.
“Cloud security is simple, absolutely simple. Stop over com
Trendmicro
This Week in Security News: 07/10/2020
blogs_trendmicro·2020-07-10·CVSS 8.8
[HIGH] This Week in Security News: 07/10/2020
Ausnutzung von Schwachstellen
## This Week in Security News: 07/10/2020
This week, read about how fifteen billion usernames and passwords for a range of internet services are currently for sale on underground forums.
By: Jon Clay Jul 10, 2020 Read time: ( words)
Save to Folio
Welcome to our weekly roundup, where we share what you need to know about the cybersecurity news and events that happened over the past few days. This week, read about how fifteen billion usernames and passwords for a range of internet services are currently for sale on underground forums. Also, learn about a new Mirai variant that exploits nine vulnerabilities, most notable of which is CVE-2020-10173. Read on:
Cloud Security is Simple, Absolutely Simple.
“Cloud security is simple, absolutely simple. Stop over
Trendmicro
This Week in Security News: 07/10/2020
blogs_trendmicro·2020-07-10·CVSS 8.8
[HIGH] This Week in Security News: 07/10/2020
Sfruttamento vulnerabilità
## This Week in Security News: 07/10/2020
This week, read about how fifteen billion usernames and passwords for a range of internet services are currently for sale on underground forums.
By: Jon Clay Jul 10, 2020 Read time: ( words)
Save to Folio
Welcome to our weekly roundup, where we share what you need to know about the cybersecurity news and events that happened over the past few days. This week, read about how fifteen billion usernames and passwords for a range of internet services are currently for sale on underground forums. Also, learn about a new Mirai variant that exploits nine vulnerabilities, most notable of which is CVE-2020-10173. Read on:
Cloud Security is Simple, Absolutely Simple.
“Cloud security is simple, absolutely simple. Stop over com
Qualys
F5 BIG-IP Remote Code Execution Vulnerability (CVE-2020-5902)
blogs_qualys·2020-07-06·CVSS 9.8
CVE-2020-5902 [CRITICAL] F5 BIG-IP Remote Code Execution Vulnerability (CVE-2020-5902)
## Table of Contents
Vulnerability Details:
Exploitation:
Affected products:
Using VMDR, Identify the Presence of CVE-2020-5902 and Management Interface on F5 Big-IP Remotely
Qualys Threat Protection
Risk-Based Prioritization of F5 BIG-IP Vulnerability
Workaround
References & Sources:
Update July 10, 2020 : F5 updated their mitigation section of security advisory on July 8, 2020 at 17:00 Pacific time, and provided a new mitigation mechanism to help customers mitigate currently known unauthenticated exploits. Qualys also updated QID 38791 to reflect these changes and are available in VULNSIGS version 2.4.935-3 and above.
Update July 8, 2020 : F5 updated the security advisory again on July 8, 2020, at 09:30 PT, saying that “all previously provided mitigations are not completely eff
Qualys
F5 BIG-IP Remote Code Execution Vulnerability (CVE-2020-5902) | Qualys
blogs_qualys·2020-07-06·CVSS 9.8
CVE-2020-5902 [CRITICAL] F5 BIG-IP Remote Code Execution Vulnerability (CVE-2020-5902) | Qualys
#### Table of Contents
- Vulnerability Details:
- Exploitation:
- Affected products:
- Using VMDR, Identify the Presence of CVE-2020-5902 and Management Interface on F5 Big-IP Remotely
- Qualys Threat Protection
- Risk-Based Prioritization of F5 BIG-IP Vulnerability
- Workaround
- References & Sources:
Update July 10, 2020: F5 updated their mitigation section of security advisory on July 8, 2020 at 17:00 Pacific time, and provided a new mitigation mechanism to help customers mitigate currently known unauthenticated exploits.
Qualys also updated QID 38791 to reflect these changes and are available in VULNSIGS version 2.4.935-3 and above.
Update July 8, 2020: F5 updated the security advisory again on July 8, 2020, at 09:30 PT, saying that “all previously provided mitigations are not compl
Tenable
CVE-2020-5902: Critical Vulnerability in F5 BIG-IP Traffic Management User Interface (TMUI) Actively Exploited
blogs_tenable·2020-07-06·CVSS 9.8
[CRITICAL] CVE-2020-5902: Critical Vulnerability in F5 BIG-IP Traffic Management User Interface (TMUI) Actively Exploited
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
2020-07-01
Published