CVE-2020-5906
Last modified
CVE-2020-5906 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. In versions 13.1.0-13.1.3.3, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, the BIG-IP system does not properly enforce the access controls for the scp.blacklist files. This allows Admin and Resource Admin users with Secure Copy (SCP) protocol access to read and overwrite blacklisted files via SCP.. EPSS estimates a 1.19% chance of exploitation in the next 30 days.
Description
In versions 13.1.0-13.1.3.3, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, the BIG-IP system does not properly enforce the access controls for the scp.blacklist files. This allows Admin and Resource Admin users with Secure Copy (SCP) protocol access to read and overwrite blacklisted files via SCP.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| F5 | Big-Ip Access Policy Manager | >= 11.6.1, <= 11.6.5 |
| F5 | Big-Ip Access Policy Manager | >= 12.1.0, <= 12.1.5 |
| F5 | Big-Ip Access Policy Manager | >= 13.1.0, <= 13.1.3 |
| F5 | Big-Ip Advanced Firewall Manager | >= 11.6.1, <= 11.6.5 |
| F5 | Big-Ip Advanced Firewall Manager | >= 12.1.0, <= 12.1.5 |
| F5 | Big-Ip Advanced Firewall Manager | >= 13.1.0, <= 13.1.3 |
| F5 | Big-Ip Analytics | >= 11.6.1, <= 11.6.5 |
| F5 | Big-Ip Analytics | >= 12.1.0, <= 12.1.5 |
| F5 | Big-Ip Analytics | >= 13.1.0, <= 13.1.3 |
| F5 | Big-Ip Application Acceleration Manager | >= 11.6.1, <= 11.6.5 |
| F5 | Big-Ip Application Acceleration Manager | >= 12.1.0, <= 12.1.5 |
| F5 | Big-Ip Application Acceleration Manager | >= 13.1.0, <= 13.1.3 |
| F5 | Big-Ip Application Security Manager | >= 11.6.1, <= 11.6.5 |
| F5 | Big-Ip Application Security Manager | >= 12.1.0, <= 12.1.5 |
| F5 | Big-Ip Application Security Manager | >= 13.1.0, <= 13.1.3 |
| F5 | Big-Ip Domain Name System | >= 11.6.1, <= 11.6.5 |
| F5 | Big-Ip Domain Name System | >= 12.1.0, <= 12.1.5 |
| F5 | Big-Ip Domain Name System | >= 13.1.0, <= 13.1.3 |
| F5 | Big-Ip Fraud Protection Service | >= 11.6.1, <= 11.6.5 |
| F5 | Big-Ip Fraud Protection Service | >= 12.1.0, <= 12.1.5 |
| F5 | Big-Ip Fraud Protection Service | >= 13.1.0, <= 13.1.3 |
| F5 | Big-Ip Global Traffic Manager | >= 11.6.1, <= 11.6.5 |
| F5 | Big-Ip Global Traffic Manager | >= 12.1.0, <= 12.1.5 |
| F5 | Big-Ip Global Traffic Manager | >= 13.1.0, <= 13.1.3 |
| F5 | Big-Ip Link Controller | >= 11.6.1, <= 11.6.5 |
| F5 | Big-Ip Link Controller | >= 12.1.0, <= 12.1.5 |
| F5 | Big-Ip Link Controller | >= 13.1.0, <= 13.1.3 |
| F5 | Big-Ip Local Traffic Manager | >= 11.6.1, <= 11.6.5 |
| F5 | Big-Ip Local Traffic Manager | >= 12.1.0, <= 12.1.5 |
| F5 | Big-Ip Local Traffic Manager | >= 13.1.0, <= 13.1.3 |
| F5 | Big-Ip Policy Enforcement Manager | >= 11.6.1, <= 11.6.5 |
| F5 | Big-Ip Policy Enforcement Manager | >= 12.1.0, <= 12.1.5 |
| F5 | Big-Ip Policy Enforcement Manager | >= 13.1.0, <= 13.1.3 |
References
- https://support.f5.com/csp/article/K82518062Vendor Advisory
- https://www.kb.cert.org/vuls/id/290915Third Party Advisory, US Government Resource
- https://support.f5.com/csp/article/K82518062Vendor Advisory
- https://www.kb.cert.org/vuls/id/290915Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-5906?
How severe is CVE-2020-5906?
How do I fix CVE-2020-5906?
Are you affected by CVE-2020-5906?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
