CVE-2020-5921Uncontrolled Resource Consumption in F5 Big-ip Access Policy Manager

Severity
7.5HIGHNVD
EPSS
0.6%
top 29.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 26
Latest updateMay 24

Description

in BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.6, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2, Syn flood causes large number of MCPD context messages destined to secondary blades consuming memory leading to MCPD failure. This issue affects only VIPRION hosts with two or more blades installed. Single-blade VIPRION hosts are not affected.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages12 packages

NVDf5/big-ip_analytics12.1.012.1.5.2+3
NVDf5/big-ip_link_controller12.1.012.1.5.2+3
NVDf5/big-ip_domain_name_system12.1.012.1.5.2+3
NVDf5/big-ip_access_policy_manager12.1.012.1.5.2+3
NVDf5/big-ip_local_traffic_manager12.1.012.1.5.2+3

🔴Vulnerability Details

2
GHSA
GHSA-3wm8-xffc-5pg9: in BIG-IP versions 152022-05-24
CVEList
CVE-2020-5921: in BIG-IP versions 152020-08-26

📋Vendor Advisories

1
F5
CVE-2020-5921: in BIG-IP versions 152020-08-26
CVE-2020-5921 — Uncontrolled Resource Consumption in F5 | cvebase