Weak Authentication and Encryption Flaw in F5 BIG-IP Products
CVE-2020-5860
What is CVE-2020-5860?
A security issue exists in F5's BIG-IP and BIG-IQ products which affects the High Availability (HA) network failover process within the Device Service Cluster (DSC). This flaw allows failover actions without the necessity of strong authentication measures, and the network traffic associated with the HA failover is not secured by Transport Layer Security (TLS). This lack of robust authentication and encryption could expose systems to potential unauthorized access and data interception risks, making it crucial for users to take necessary security measures.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
BIG-IP, BIG-IQ BIG-IP 15.0.0-15.1.0.2, 14.1.0-14.1.2.3, 13.1.0-13.1.3.2, 12.1.0-12.1.5.1, 11.5.2-11.6.5.1
BIG-IP, BIG-IQ BIG-IQ 7.0.0, 6.0.0-6.1.0, 5.2.0-5.4.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved