PT-2020-18831 · F5 · Big-Ip

Published

2020-10-29

·

Updated

2020-11-09

·

CVE-2020-5933

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions BIG-IP versions 11.6.1 through 11.6.5.1 BIG-IP versions 12.1.0 through 12.1.5.1 BIG-IP versions 13.1.0 through 13.1.3.4 BIG-IP versions 14.1.0 through 14.1.2.3 BIG-IP versions 15.1.0 through 15.1.0.5
Description When a BIG-IP system that has a virtual server configured with an HTTP compression profile processes compressed HTTP message payloads that require deflation, a Slowloris-style attack can trigger an out-of-memory condition on the BIG-IP system.
Recommendations For BIG-IP versions 11.6.1 through 11.6.5.1, consider disabling the HTTP compression profile until a patch is available. For BIG-IP versions 12.1.0 through 12.1.5.1, consider disabling the HTTP compression profile until a patch is available. For BIG-IP versions 13.1.0 through 13.1.3.4, consider disabling the HTTP compression profile until a patch is available. For BIG-IP versions 14.1.0 through 14.1.2.3, consider disabling the HTTP compression profile until a patch is available. For BIG-IP versions 15.1.0 through 15.1.0.5, consider disabling the HTTP compression profile until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-5933

Affected Products

Big-Ip