CVE-2020-5919
published 2020-08-26CVE-2020-5919: In versions 15.1.0-15.1.0.4, rendering of certain session variables by BIG-IP APM UI-based agents in an access profile configured with Modern customization…
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.04%
60.3th percentile
In versions 15.1.0-15.1.0.4, rendering of certain session variables by BIG-IP APM UI-based agents in an access profile configured with Modern customization, may cause the Traffic Management Microkernel (TMM) to stop responding.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip_access_policy_manager | >= 15.1.0 < 15.1.0.5 | 15.1.0.5 |
| f5 | big-ip_apm | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
F5
CVE-2020-5919: In versions 15
vendor_f5·2020-08-26·CVSS 7.5
CVE-2020-5919 [HIGH] CVE-2020-5919: In versions 15
CVE-2020-5919: In versions 15
In versions 15.1.0-15.1.0.4, rendering of certain session variables by BIG-IP APM UI-based agents in an access profile configured with Modern customization, may cause the Traffic Management Microkernel (TMM) to stop responding.
Affected Products: BIG-IP APM
Affected Versions: 15.1.0 - 15.1.0.5
F5 Advisory Articles: K94563369
F5 References: https://support.f5.com/csp/article/K94563369
GHSA
GHSA-c66g-5x8m-4p5q: In versions 15
ghsa_unreviewed·2022-05-24
CVE-2020-5919 [MEDIUM] GHSA-c66g-5x8m-4p5q: In versions 15
In versions 15.1.0-15.1.0.4, rendering of certain session variables by BIG-IP APM UI-based agents in an access profile configured with Modern customization, may cause the Traffic Management Microkernel (TMM) to stop responding.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-08-26
Published