MEDIUM
On BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, FPS, GTM, Link Controller, PEM) versions 15.1.0-15.1.0.5, 14.1.0-14.1.2.3, and 13.1.0-13.1.3.3, when handling MQTT traffic through a BIG-IP virtual server associated with an MQTT profile and an iRule performing manipulations on that traffic, TMM may produce a core file
Published Oct 29, 2020
5.9
MEDIUMCVSS 3.1
EPSS 0.81%
Description
On BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, FPS, GTM, Link Controller, PEM) versions 15.1.0-15.1.0.5, 14.1.0-14.1.2.3, and 13.1.0-13.1.3.3, when handling MQTT traffic through a BIG-IP virtual server associated with an MQTT profile and an iRule performing manipulations on that traffic, TMM may produce a core file.
Affected products
- Vendor n/a Product BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, FPS, GTM, Link Controller, PEM) Defaultn/a
- Version 15.1.0-15.1.0.5, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, FPS, GTM, Link Controller, PEM) | n/a |
|
OR
- ≥ 13.1.0 · < 13.1.3.4
- ≥ 14.1.0 · < 14.1.2.4
- ≥ 15.0.0 · < 15.1.1
- ≥ 13.1.0 · < 13.1.3.4
- ≥ 14.1.0 · < 14.1.2.4
- ≥ 15.0.0 · < 15.1.1
- ≥ 13.1.0 · < 13.1.3.4
- ≥ 14.1.0 · < 14.1.2.4
- ≥ 15.0.0 · < 15.1.1
- ≥ 13.1.0 · < 13.1.3.4
- ≥ 14.1.0 · < 14.1.2.4
- ≥ 15.0.0 · < 15.1.1
- ≥ 13.1.0 · < 13.1.3.4
- ≥ 14.1.0 · < 14.1.2.4
- ≥ 15.0.0 · < 15.1.1
- ≥ 13.1.0 · < 13.1.3.4
- ≥ 14.1.0 · < 14.1.2.4
- ≥ 15.0.0 · < 15.1.1
- ≥ 13.1.0 · < 13.1.3.4
- ≥ 14.1.0 · < 14.1.2.4
- ≥ 15.0.0 · < 15.1.1
- ≥ 13.1.0 · < 13.1.3.4
- ≥ 14.1.0 · < 14.1.2.4
- ≥ 15.0.0 · < 15.1.1
- ≥ 13.1.0 · < 13.1.3.4
- ≥ 14.1.0 · < 14.1.2.4
- ≥ 15.0.0 · < 15.1.1
- ≥ 13.1.0 · < 13.1.3.4
- ≥ 14.1.0 · < 14.1.2.4
- ≥ 15.0.0 · < 15.1.1
- ≥ 13.1.0 · < 13.1.3.4
- ≥ 14.1.0 · < 14.1.2.4
- ≥ 15.0.0 · < 15.1.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-27089 Advisory
- https://support.f5.com/csp/article/K62830532 x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-27089 | Advisory | |
| https://support.f5.com/csp/article/K62830532 | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner f5
Published Oct 29, 2020
Updated Aug 4, 2024
Reserved Jan 6, 2020
Link CVE-2020-5935
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2020-27089 Assigner f5
Published Oct 29, 2020
Updated Aug 4, 2024
Exploited since n/a
Link EUVD-2020-27089