Lucene search

K
f5F5F5:K31301245
HistoryJul 01, 2020 - 12:00 a.m.

K31301245 : TMUI CSRF vulnerability CVE-2020-5904

2020-07-0100:00:00
my.f5.com
43

AI Score

7.2

Confidence

Low

EPSS

0.001

Percentile

43.9%

Security Advisory Description

A cross-site request forgery (CSRF) vulnerability in the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, exists in an undisclosed page. (CVE-2020-5904)

Impact

An attacker may be able to use the session of an administrator user to execute TMOS Shell (tmsh) commands on the BIG-IP system. This vulnerability affects only the control plane, and an administrator user must be logged in for the exploit to be possible.

AI Score

7.2

Confidence

Low

EPSS

0.001

Percentile

43.9%