Use-After-Free Memory Vulnerability in BIG-IP Edge Client by F5 Networks
CVE-2020-5897

8.8HIGH

Key Information:

Vendor
F5
Vendor
CVE Published:
12 May 2020

Summary

A use-after-free memory vulnerability exists in the BIG-IP Edge Client's Windows ActiveX component, impacting versions 7.1.5 through 7.1.9. This flaw can potentially allow an attacker to execute arbitrary code through malicious manipulation of the affected component. Users are advised to update to the latest versions to mitigate risks associated with this vulnerability.

Affected Version(s)

F5 Edge Client 7.1.5-7.1.9

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.