Weak File and Folder Permissions in BIG-IP Edge Client by F5 Networks
CVE-2020-5896

7.8HIGH

Key Information:

Vendor
F5
Vendor
CVE Published:
12 May 2020

Summary

The BIG-IP Edge Client from F5 Networks has a vulnerability in its Windows Installer Service, specifically affecting versions 7.1.5 to 7.1.9. This vulnerability arises from weak file and folder permissions in the application's temporary directory. Such misconfigurations could allow unauthorized users to access or modify sensitive data, leading to potential exploitation and data leakage.

Affected Version(s)

F5 Edge Client 7.1.5-7.1.9

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.