CVE-2020-5902

CVE Published 2020-07-01
Related CWE(s) CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Related Vendor(s) f5
Related Product(s) big-ip_policy_enforcement_manager, big-ip_domain_name_system, big-ip_advanced_web_application_firewall, big-ip_fraud_protection_service, big-ip_application_security_manager, big-ip_application_acceleration_manager, big-ip_global_traffic_manager, big-ip_local_traffic_manager, big-ip_analytics, big-ip_advanced_firewall_manager, big-ip_link_controller, ssl_orchestrator, big-ip_ddos_hybrid_defender, big-ip_access_policy_manager
Exploitation Reported (CISA KEV) 2021-11-03
CVSS 3 Base Score 9.8 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulnerability in undisclosed pages.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References