Vulnerabilities > CVE-2020-5874 - Unspecified vulnerability in F5 Big-Ip Access Policy Manager
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
HIGH Summary
On BIG-IP APM 15.0.0-15.0.1.2, 14.1.0-14.1.2.3, and 14.0.0-14.0.1, in certain circumstances, an attacker sending specifically crafted requests to a BIG-IP APM virtual server may cause a disruption of service provided by the Traffic Management Microkernel(TMM).
Vulnerable Configurations
Nessus
NASL family | F5 Networks Local Security Checks |
NASL id | F5_BIGIP_SOL46901953.NASL |
description | In certain circumstances, an attacker sending specifically crafted requests to aBIG-IP APM virtual server may cause a disruption of service provided by the Traffic Management Microkernel(TMM). (CVE-2020-5874) Impact An attacker may be able to perform a denial-of-service (DoS) attack on a BIG-IP system by causing the TMM process to restart. The data plane is only impacted and exposed when the virtual server is configured to use OpenID connect. The control plane is not impacted by this vulnerability. |
last seen | 2020-05-09 |
modified | 2020-04-30 |
plugin id | 136139 |
published | 2020-04-30 |
reporter | This script is Copyright (C) 2020 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/136139 |
title | F5 Networks BIG-IP : BIG-IP APM virtual server vulnerability (K46901953) |