TCP Sequence Number Exposure in F5 BIG-IP Products
CVE-2020-5947
Key Information:
- Vendor
- F5
- Vendor
- CVE Published:
- 19 November 2020
Summary
In specific versions of F5 BIG-IP systems, attackers might exploit a flaw that allows them to retrieve TCP sequence numbers. This can lead to potential reuse of these numbers in subsequent connections, targeting the same source and destination IP addresses and ports. The affected BIG-IP platforms stand vulnerable to unauthorized access, enabling malicious actors to compromise the integrity of network communications. Users of the impacted models should take immediate action to mitigate potential risks and apply available patches.
Affected Version(s)
BIG-IP 2000 series (C112), BIG-IP 4000 series (C113), BIG-IP i2000 series (C117), BIG-IP i4000 series (C115), BIG-IP Virtual Edition (VE) 16.0.0-16.0.0.1
BIG-IP 2000 series (C112), BIG-IP 4000 series (C113), BIG-IP i2000 series (C117), BIG-IP i4000 series (C115), BIG-IP Virtual Edition (VE) 15.1.0-15.1.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved