TCP Sequence Number Exposure in F5 BIG-IP Products
CVE-2020-5947

4.3MEDIUM

Summary

In specific versions of F5 BIG-IP systems, attackers might exploit a flaw that allows them to retrieve TCP sequence numbers. This can lead to potential reuse of these numbers in subsequent connections, targeting the same source and destination IP addresses and ports. The affected BIG-IP platforms stand vulnerable to unauthorized access, enabling malicious actors to compromise the integrity of network communications. Users of the impacted models should take immediate action to mitigate potential risks and apply available patches.

Affected Version(s)

BIG-IP 2000 series (C112), BIG-IP 4000 series (C113), BIG-IP i2000 series (C117), BIG-IP i4000 series (C115), BIG-IP Virtual Edition (VE) 16.0.0-16.0.0.1

BIG-IP 2000 series (C112), BIG-IP 4000 series (C113), BIG-IP i2000 series (C117), BIG-IP i4000 series (C115), BIG-IP Virtual Edition (VE) 15.1.0-15.1.1

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.