PT-2020-18847 · F5 · F5 Big-Ip

Published

2020-12-11

·

Updated

2020-12-16

·

CVE-2020-5949

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions F5 BIG-IP versions 13.1.0 through 13.1.3.4 F5 BIG-IP versions 14.0.0 through 14.0.1
Description A certain traffic pattern sent to a virtual server configured with an FTP profile can cause the FTP channel to break.
Recommendations For F5 BIG-IP versions 13.1.0 through 13.1.3.4, consider restricting access to the FTP profile until a patch is available. For F5 BIG-IP versions 14.0.0 through 14.0.1, consider restricting access to the FTP profile until a patch is available. As a temporary workaround, consider disabling the FTP profile on virtual servers to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-5949

Affected Products

F5 Big-Ip