MQTT Traffic Vulnerability in BIG-IP Products by F5 Networks
CVE-2020-5935
5.9MEDIUM
Key Information:
- Vendor
F5
- Vendor
- CVE Published:
- 29 October 2020
What is CVE-2020-5935?
A vulnerability exists in the F5 BIG-IP product line that can result in core file generation when handling MQTT traffic. Specifically, this issue arises when utilizing an MQTT profile alongside an iRule that manipulates the traffic on a BIG-IP virtual server. Affected versions include 15.1.0 through 15.1.0.5, as well as earlier versions such as 14.1.0 through 14.1.2.3 and 13.1.0 through 13.1.3.3. This could potentially impact the stability and performance of systems that rely on the BIG-IP platform for managing MQTT traffic.
Affected Version(s)
BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, FPS, GTM, Link Controller, PEM) 15.1.0-15.1.0.5, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3