PT-2020-16775 · F5 · Big-Ip

Published

2020-12-11

·

Updated

2020-12-14

·

CVE-2020-27713

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions BIG-IP version 13.1.3.4
Description The issue occurs when a BIG-IP AFM HTTP security profile is applied to a virtual server and the system receives a request with specific characteristics, causing the connection to reset and the Traffic Management Microkernel (TMM) to leak memory.
Recommendations For version 13.1.3.4, consider restricting the use of BIG-IP AFM HTTP security profiles on virtual servers until a fix is available. As a temporary workaround, review and adjust the configuration to minimize the risk of memory leaks in the Traffic Management Microkernel (TMM).

Fix

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-27713

Affected Products

Big-Ip