VulnerabilityModified
CVE-2020-5906
This allows Admin and Resource Admin users with Secure Copy (SCP) protocol access to read and overwrite blacklisted files via SCP.
HIGH 8.1EPSS 1.19%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.19%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In versions 13.1.0-13.1.3.3, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, the BIG-IP system does not properly enforce the access controls for the scp.blacklist files. This allows Admin and Resource Admin users with Secure Copy (SCP) protocol access to read and overwrite blacklisted files via SCP.
- CVSS 3.1
- 8.1 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 1.19% probability · 66th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-276
- Affected
- f5/big-ip access policy manager · f5/big-ip advanced firewall manager · f5/big-ip analytics · f5/big-ip application acceleration manager · f5/big-ip application security manager · f5/big-ip domain name system · f5/big-ip fraud protection service · f5/big-ip global traffic manager · f5/big-ip link controller · f5/big-ip local traffic manager · f5/big-ip policy enforcement manager
- Source
- f5sirt@f5.com
References
- https://support.f5.com/csp/article/K82518062Vendor Advisory
- https://www.kb.cert.org/vuls/id/290915Third Party Advisory, US Government Resource
- https://support.f5.com/csp/article/K82518062Vendor Advisory
- https://www.kb.cert.org/vuls/id/290915Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.