PT-2020-18755 · F5 · F5 Big-Ip
Published
2020-01-14
·
Updated
2020-01-29
·
CVE-2020-5851
CVSS v3.1
4.6
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
F5 BIG-IP versions with specific engineering hotfixes, including Hotfix-BIGIP-14.1.0.2.0.45.4-ENG and Hotfix-BIGIP-14.1.0.2.0.62.4-ENG
Description
The issue affects the Trusted Platform Module (TPM) system integrity check, which cannot detect modifications to specific system components on impacted versions and platforms. This issue is limited to specific engineering hotfixes and platforms.
Recommendations
For Hotfix-BIGIP-14.1.0.2.0.45.4-ENG, consider applying a newer hotfix that addresses the issue.
For Hotfix-BIGIP-14.1.0.2.0.62.4-ENG, consider applying a newer hotfix that addresses the issue.
As a temporary workaround, consider restricting access to system components that may be modified to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
F5 Big-Ip