CVE-2020-5892
30.04.2020, 22:15
In versions 7.1.5-7.1.8, the BIG-IP Edge Client components in BIG-IP APM, Edge Gateway, and FirePass legacy allow attackers to obtain the full session ID from process memory.Enginsight
Vendor | Product | Version |
---|---|---|
f5 | big-ip_access_policy_manager | 11.6.1 ≤ 𝑥 ≤ 11.6.5 |
f5 | big-ip_access_policy_manager | 12.1.0 ≤ 𝑥 ≤ 12.1.5 |
f5 | big-ip_access_policy_manager | 13.0.0 ≤ 𝑥 ≤ 13.1.3 |
f5 | big-ip_access_policy_manager | 14.0.0 ≤ 𝑥 ≤ 14.1.2 |
f5 | big-ip_access_policy_manager | 15.0.0 ≤ 𝑥 ≤ 15.1.0 |
f5 | big-ip_access_policy_manager_client | 7.1.5 ≤ 𝑥 ≤ 7.1.8 |
f5 | big-ip_edge_gateway | 11.6.1 ≤ 𝑥 ≤ 11.6.5 |
f5 | big-ip_edge_gateway | 12.1.0 ≤ 𝑥 ≤ 12.1.5 |
f5 | big-ip_edge_gateway | 13.0.0 ≤ 𝑥 ≤ 13.1.3 |
f5 | big-ip_edge_gateway | 14.0.0 ≤ 𝑥 ≤ 14.1.2 |
f5 | big-ip_edge_gateway | 15.0.0 ≤ 𝑥 ≤ 15.1.0 |
𝑥
= Vulnerable software versions