<img alt="" src="https://secure.hiss3lark.com/173130.png" style="display:none;">

 

Blog

Read or download all Datashield news, reviews, content, and more.

 

All Posts

Vulnerability CVE-2020-5902

Vulnerability CVE-2020-5902

Datashield is aware of a recent vulnerability [CVE-2020-5902] and it has been published for the following F5 products: BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, FPS, GTM, Link Controller, PEM)

This vulnerability affects the Traffic Management User Interface (TMUI), also known as the configuration utility. This is a unauthenticated Remote Code Execution (RCE) vulnerability that allows attackers to execute system commands, create or delete files, disable services, and execute java code. This CVE was rated as a 10 on the CSVSv3 scale. We recommend immediate patching to ensure the vulnerability isn’t leveraged in any attack against your network.

The vulnerable versions, their subsequent hotfixes, and a more granular review of the vulnerability can be found using the link provided below.

https://support.f5.com/csp/article/K52145254

Datashield performed a preliminary scan against the external networks that we had on file, looking for any exposed management interfaces and found none. However, we do want to recommend patching and having your admins ensure that the TMUI is not exposed to the internet. There is also currently no known POC (proof of concept) for this vulnerability.

If you have any questions regarding this vulnerability, please contact us.

Topics from this Article

Microsoft, Windows, Remote Code Execution, CVE, Vulnerability Management

Datashield
Datashield
Official Datashield account for blog content, news, announcements and more. The articles authored include a collaboration between internal staff, specifically the security operations and marketing team.

Related Posts

Lumifi Cyber Acquires Datashield to Deliver Next-Generation Managed Detection and Response

Combines AI and Machine Learning-Based Software with MDR Services to Provide Fortune 500-Grade Security to Companies of All Sizes Palm Desert, CA and Scottsdale, AZ — May 3, 2022 — Lumifi Cyber, Inc., a next-generation managed detection and response (MDR) cybersecurity software provider, today announced its acquisition of Datashield, Inc., an end-to-end cybersecurity resilience services provider, to deliver Fortune 500-grade security to companies of all sizes for an affordable monthly price.

Datashield Becomes Member of Microsoft Intelligent Security Association (MISA)

Datashield Becomes Member of Microsoft Intelligent Security Association (MISA)

The Difference Between Cybersecurity & Network Security

The Difference Between Cybersecurity & Network Security