ID

VAR-202008-0941


CVE

CVE-2020-5925


TITLE

plural BIG-IP Product Exceptional State Check Vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2020-008725

DESCRIPTION

In BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.6, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, undisclosed internally generated UDP traffic may cause the Traffic Management Microkernel (TMM) to restart under some circumstances. plural BIG-IP The product contains an exceptional condition check vulnerability.Service operation interruption (DoS) It may be put into a state. F5 BIG-IP is a F5 load balancing device. F5 BIG-IP has security loopholes in processing UDP protocol data. Remote attackers can use this loophole to submit special requests to restart TMM and cause denial of service attacks. BIG-IP version 15.1.0 to 15.1.0.4, version 15.0.0 to 15.0.1.3, version 14.1.0 to 14.1.2.3, version 13.1.0 to 13.1.3.3, 12.1.0 Versions up to 12.1.5.1 and versions between 11.6.1 and 11.6.5.1 have security vulnerabilities

Trust: 2.25

sources: NVD: CVE-2020-5925 // JVNDB: JVNDB-2020-008725 // CNVD: CNVD-2020-50115 // VULHUB: VHN-184050

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2020-50115

AFFECTED PRODUCTS

vendor:f5model:big-ip domain name systemscope:ltversion:12.1.5.2

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:ltversion:11.6.5.2

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:ltversion:15.1.0.5

Trust: 1.0

vendor:f5model:big-ip analyticsscope:ltversion:11.6.5.2

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:ltversion:13.1.3.4

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:ltversion:14.1.2.7

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:gteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:ltversion:13.1.3.4

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:ltversion:11.6.5.2

Trust: 1.0

vendor:f5model:big-ip analyticsscope:ltversion:12.1.5.2

Trust: 1.0

vendor:f5model:big-ip application security managerscope:gteversion:11.6.1

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:ltversion:13.1.3.4

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:ltversion:13.1.3.4

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:gteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:ltversion:15.0.1.4

Trust: 1.0

vendor:f5model:big-ip analyticsscope:ltversion:13.1.3.4

Trust: 1.0

vendor:f5model:big-ip analyticsscope:ltversion:14.1.2.7

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:ltversion:11.6.5.2

Trust: 1.0

vendor:f5model:big-ip application security managerscope:gteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:gteversion:11.6.1

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:gteversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:ltversion:13.1.3.4

Trust: 1.0

vendor:f5model:big-ip link controllerscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:gteversion:15.0.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:ltversion:11.6.5.2

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:ltversion:11.6.5.2

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:ltversion:15.1.0.5

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:gteversion:15.0.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:gteversion:11.6.1

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:ltversion:13.1.3.4

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:gteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:gteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:ltversion:15.1.0.5

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:ltversion:15.1.0.5

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:ltversion:13.1.3.4

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:gteversion:11.6.1

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:ltversion:13.1.3.4

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:gteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:ltversion:13.1.3.4

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:ltversion:15.0.1.4

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:ltversion:15.1.0.5

Trust: 1.0

vendor:f5model:big-ip analyticsscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:gteversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:ltversion:11.6.5.2

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:ltversion:15.0.1.4

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:ltversion:15.0.1.4

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:ltversion:15.1.0.5

Trust: 1.0

vendor:f5model:big-ip analyticsscope:gteversion:11.6.1

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:gteversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:gteversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:ltversion:11.6.5.2

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:gteversion:15.0.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:ltversion:15.0.1.4

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:ltversion:15.1.0.5

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:gteversion:11.6.1

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:gteversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:ltversion:11.6.5.2

Trust: 1.0

vendor:f5model:big-ip link controllerscope:ltversion:13.1.3.4

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:gteversion:15.0.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:gteversion:15.0.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:ltversion:15.1.0.5

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:ltversion:12.1.5.2

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:ltversion:15.0.1.4

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:gteversion:11.6.1

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:ltversion:14.1.2.7

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:gteversion:15.0.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:gteversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:ltversion:12.1.5.2

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:ltversion:12.1.5.2

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:ltversion:15.0.1.4

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:ltversion:14.1.2.7

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:ltversion:14.1.2.7

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:gteversion:11.6.1

Trust: 1.0

vendor:f5model:big-ip application security managerscope:ltversion:15.0.1.4

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:gteversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:ltversion:12.1.5.2

Trust: 1.0

vendor:f5model:big-ip link controllerscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:gteversion:15.0.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:gteversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:ltversion:15.1.0.5

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:ltversion:14.1.2.7

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:gteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:gteversion:15.0.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:ltversion:12.1.5.2

Trust: 1.0

vendor:f5model:big-ip application security managerscope:ltversion:11.6.5.2

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:ltversion:15.1.0.5

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:ltversion:14.1.2.7

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:gteversion:11.6.1

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:ltversion:12.1.5.2

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:gteversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:ltversion:15.0.1.4

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:ltversion:12.1.5.2

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:ltversion:14.1.2.7

Trust: 1.0

vendor:f5model:big-ip link controllerscope:gteversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:ltversion:12.1.5.2

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:ltversion:14.1.2.7

Trust: 1.0

vendor:f5model:big-ip application security managerscope:ltversion:14.1.2.7

Trust: 1.0

vendor:f5model:big-ip analyticsscope:ltversion:15.1.0.5

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:gteversion:15.0.0

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:ltversion:15.0.1.4

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:gteversion:11.6.1

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:gteversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:gteversion:15.0.0

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:gteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:gteversion:11.6.1

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:gteversion:15.0.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:gteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:ltversion:11.6.5.2

Trust: 1.0

vendor:f5model:big-ip analyticsscope:gteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:ltversion:15.0.1.4

Trust: 1.0

vendor:f5model:big-ip link controllerscope:ltversion:12.1.5.2

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:ltversion:14.1.2.7

Trust: 1.0

vendor:f5model:big-ip application security managerscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:gteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip advanced firewall managerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip analyticsscope: - version: -

Trust: 0.8

vendor:f5model:big-ip application acceleration managerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip application security managerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip domain name systemscope: - version: -

Trust: 0.8

vendor:f5model:big-ip fraud protection servicescope: - version: -

Trust: 0.8

vendor:f5model:big-ip global traffic managerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip link controllerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip local traffic managerscope: - version: -

Trust: 0.8

vendor:f5model:big-ipscope:gteversion:14.1.0,<=14.1.2.3

Trust: 0.6

vendor:f5model:big-ipscope:gteversion:13.1.0,<=13.1.3.3

Trust: 0.6

vendor:f5model:big-ipscope:gteversion:12.1.0,<=12.1.5.1

Trust: 0.6

vendor:f5model:big-ipscope:gteversion:11.6.1,<=11.6.5.1

Trust: 0.6

vendor:f5model:big-ipscope:gteversion:15.1.0,<=15.1.0.4

Trust: 0.6

vendor:f5model:big-ipscope:gteversion:15.0.0,<=15.0.1.3

Trust: 0.6

sources: CNVD: CNVD-2020-50115 // JVNDB: JVNDB-2020-008725 // NVD: CVE-2020-5925

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-5925
value: HIGH

Trust: 1.0

NVD: JVNDB-2020-008725
value: HIGH

Trust: 0.8

CNVD: CNVD-2020-50115
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-202008-1222
value: HIGH

Trust: 0.6

VULHUB: VHN-184050
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2020-5925
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

NVD: JVNDB-2020-008725
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

CNVD: CNVD-2020-50115
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-184050
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2020-5925
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: JVNDB-2020-008725
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2020-50115 // VULHUB: VHN-184050 // JVNDB: JVNDB-2020-008725 // CNNVD: CNNVD-202008-1222 // NVD: CVE-2020-5925

PROBLEMTYPE DATA

problemtype:CWE-754

Trust: 1.9

sources: VULHUB: VHN-184050 // JVNDB: JVNDB-2020-008725 // NVD: CVE-2020-5925

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202008-1222

TYPE

code problem

Trust: 0.6

sources: CNNVD: CNNVD-202008-1222

CONFIGURATIONS

sources: JVNDB: JVNDB-2020-008725

PATCH

title:K45421311url:https://support.f5.com/csp/article/K45421311

Trust: 0.8

title:Patch for F5 BIG-IP UDP request denial of service vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/232786

Trust: 0.6

title:BIG-IP Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=127301

Trust: 0.6

sources: CNVD: CNVD-2020-50115 // JVNDB: JVNDB-2020-008725 // CNNVD: CNNVD-202008-1222

EXTERNAL IDS

db:NVDid:CVE-2020-5925

Trust: 3.1

db:JVNDBid:JVNDB-2020-008725

Trust: 0.8

db:CNVDid:CNVD-2020-50115

Trust: 0.7

db:CNNVDid:CNNVD-202008-1222

Trust: 0.7

db:AUSCERTid:ESB-2020.2928.2

Trust: 0.6

db:AUSCERTid:ESB-2020.2928

Trust: 0.6

db:AUSCERTid:ESB-2020.2928.3

Trust: 0.6

db:VULHUBid:VHN-184050

Trust: 0.1

sources: CNVD: CNVD-2020-50115 // VULHUB: VHN-184050 // JVNDB: JVNDB-2020-008725 // CNNVD: CNNVD-202008-1222 // NVD: CVE-2020-5925

REFERENCES

url:https://nvd.nist.gov/vuln/detail/cve-2020-5925

Trust: 2.0

url:https://support.f5.com/csp/article/k45421311

Trust: 1.7

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2020-5925

Trust: 0.8

url:https://vigilance.fr/vulnerability/f5-big-ip-denial-of-service-via-udp-33160

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2020.2928/

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2020.2928.2/

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2020.2928.3/

Trust: 0.6

sources: CNVD: CNVD-2020-50115 // VULHUB: VHN-184050 // JVNDB: JVNDB-2020-008725 // CNNVD: CNNVD-202008-1222 // NVD: CVE-2020-5925

SOURCES

db:CNVDid:CNVD-2020-50115
db:VULHUBid:VHN-184050
db:JVNDBid:JVNDB-2020-008725
db:CNNVDid:CNNVD-202008-1222
db:NVDid:CVE-2020-5925

LAST UPDATE DATE

2024-11-23T23:11:18.344000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2020-50115date:2020-09-02T00:00:00
db:VULHUBid:VHN-184050date:2020-08-31T00:00:00
db:JVNDBid:JVNDB-2020-008725date:2020-09-18T00:00:00
db:CNNVDid:CNNVD-202008-1222date:2020-10-22T00:00:00
db:NVDid:CVE-2020-5925date:2024-11-21T05:34:50.353

SOURCES RELEASE DATE

db:CNVDid:CNVD-2020-50115date:2020-09-02T00:00:00
db:VULHUBid:VHN-184050date:2020-08-26T00:00:00
db:JVNDBid:JVNDB-2020-008725date:2020-09-18T00:00:00
db:CNNVDid:CNNVD-202008-1222date:2020-08-26T00:00:00
db:NVDid:CVE-2020-5925date:2020-08-26T16:15:12.887