CVE Vulnerabilities

CVE-2020-5921

Published: Aug 26, 2020 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

in BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.6, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2, Syn flood causes large number of MCPD context messages destined to secondary blades consuming memory leading to MCPD failure. This issue affects only VIPRION hosts with two or more blades installed. Single-blade VIPRION hosts are not affected.

Affected Software

NameVendorStart VersionEnd Version
Big-ip_access_policy_managerF512.1.0 (including)12.1.5.2 (excluding)
Big-ip_access_policy_managerF514.1.0 (including)14.1.2.7 (excluding)
Big-ip_access_policy_managerF515.0.0 (including)15.0.1.4 (excluding)
Big-ip_access_policy_managerF515.1.0 (including)15.1.0.5 (excluding)
Big-ip_advanced_firewall_managerF512.1.0 (including)12.1.5.2 (excluding)
Big-ip_advanced_firewall_managerF514.1.0 (including)14.1.2.7 (excluding)
Big-ip_advanced_firewall_managerF515.0.0 (including)15.0.1.4 (excluding)
Big-ip_advanced_firewall_managerF515.1.0 (including)15.1.0.5 (excluding)
Big-ip_analyticsF512.1.0 (including)12.1.5.2 (excluding)
Big-ip_analyticsF514.1.0 (including)14.1.2.7 (excluding)
Big-ip_analyticsF515.0.0 (including)15.0.1.4 (excluding)
Big-ip_analyticsF515.1.0 (including)15.1.0.5 (excluding)
Big-ip_application_acceleration_managerF512.1.0 (including)12.1.5.2 (excluding)
Big-ip_application_acceleration_managerF514.1.0 (including)14.1.2.7 (excluding)
Big-ip_application_acceleration_managerF515.0.0 (including)15.0.1.4 (excluding)
Big-ip_application_acceleration_managerF515.1.0 (including)15.1.0.5 (excluding)
Big-ip_application_security_managerF512.1.0 (including)12.1.5.2 (excluding)
Big-ip_application_security_managerF514.1.0 (including)14.1.2.7 (excluding)
Big-ip_application_security_managerF515.0.0 (including)15.0.1.4 (excluding)
Big-ip_application_security_managerF515.1.0 (including)15.1.0.5 (excluding)
Big-ip_domain_name_systemF512.1.0 (including)12.1.5.2 (excluding)
Big-ip_domain_name_systemF514.1.0 (including)14.1.2.7 (excluding)
Big-ip_domain_name_systemF515.0.0 (including)15.0.1.4 (excluding)
Big-ip_domain_name_systemF515.1.0 (including)15.1.0.5 (excluding)
Big-ip_fraud_protection_serviceF512.1.0 (including)12.1.5.2 (excluding)
Big-ip_fraud_protection_serviceF514.1.0 (including)14.1.2.7 (excluding)
Big-ip_fraud_protection_serviceF515.0.0 (including)15.0.1.4 (excluding)
Big-ip_fraud_protection_serviceF515.1.0 (including)15.1.0.5 (excluding)
Big-ip_global_traffic_managerF512.1.0 (including)12.1.5.2 (excluding)
Big-ip_global_traffic_managerF514.1.0 (including)14.1.2.7 (excluding)
Big-ip_global_traffic_managerF515.0.0 (including)15.0.1.4 (excluding)
Big-ip_global_traffic_managerF515.1.0 (including)15.1.0.5 (excluding)
Big-ip_link_controllerF512.1.0 (including)12.1.5.2 (excluding)
Big-ip_link_controllerF514.1.0 (including)14.1.2.7 (excluding)
Big-ip_link_controllerF515.0.0 (including)15.0.1.4 (excluding)
Big-ip_link_controllerF515.1.0 (including)15.1.0.5 (excluding)
Big-ip_local_traffic_managerF512.1.0 (including)12.1.5.2 (excluding)
Big-ip_local_traffic_managerF514.1.0 (including)14.1.2.7 (excluding)
Big-ip_local_traffic_managerF515.0.0 (including)15.0.1.4 (excluding)
Big-ip_local_traffic_managerF515.1.0 (including)15.1.0.5 (excluding)
Big-ip_policy_enforcement_managerF512.1.0 (including)12.1.5.2 (excluding)
Big-ip_policy_enforcement_managerF514.1.0 (including)14.1.2.7 (excluding)
Big-ip_policy_enforcement_managerF515.0.0 (including)15.0.1.4 (excluding)
Big-ip_policy_enforcement_managerF515.1.0 (including)15.1.0.5 (excluding)

References