CVE Vulnerabilities

CVE-2020-5855

Published: Feb 06, 2020 | Modified: Jul 21, 2021
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

When the Windows Logon Integration feature is configured for all versions of BIG-IP Edge Client for Windows, unauthorized users who have physical access to an authorized users machine can get shell access under unprivileged user.

Affected Software

Name Vendor Start Version End Version
Big-ip_access_policy_manager F5 11.5.2 (including) 11.6.5 (including)
Big-ip_access_policy_manager F5 12.1.0 (including) 12.1.5 (including)
Big-ip_access_policy_manager F5 13.1.0 (including) 13.1.3 (including)
Big-ip_access_policy_manager F5 14.1.0 (including) 14.1.2 (including)
Big-ip_access_policy_manager F5 15.0.0 (including) 15.1.0 (including)
Big-ip_access_policy_manager_client F5 7.1.5 (including) 7.1.8 (including)

References