Junglewise Threat Intelligence

CVE-2020-5902: F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution Vulnerability

CVE-2020-5902 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Technologies: F5 BIG-IP. Vendors: F5.

Executive brief

The F5 BIG-IP Traffic Management User Interface (TMUI), also known as the Configuration utility, contains a remote code execution vulnerability due to improper limitation of a pathname to a restricted directory (path traversal). This allows unauthenticated attackers with network access to the TMUI to execute arbitrary system commands, create or delete files, and disable services.

Affected products

  • F5 BIG-IP 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, 11.6.1-11.6.5.1

Timeline

  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: disclosed

Related threats