PT-2020-18755 · F5 · F5 Big-Ip

Published

2020-01-14

·

Updated

2020-01-29

·

CVE-2020-5851

CVSS v3.1

4.6

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions F5 BIG-IP versions with specific engineering hotfixes, including Hotfix-BIGIP-14.1.0.2.0.45.4-ENG and Hotfix-BIGIP-14.1.0.2.0.62.4-ENG
Description The issue affects the Trusted Platform Module (TPM) system integrity check, which cannot detect modifications to specific system components on impacted versions and platforms. This issue is limited to specific engineering hotfixes and platforms.
Recommendations For Hotfix-BIGIP-14.1.0.2.0.45.4-ENG, consider applying a newer hotfix that addresses the issue. For Hotfix-BIGIP-14.1.0.2.0.62.4-ENG, consider applying a newer hotfix that addresses the issue. As a temporary workaround, consider restricting access to system components that may be modified to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-5851

Affected Products

F5 Big-Ip