SB2020121738 - Denial of service in BIG-IP AVRD
Published: December 17, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2020-27728)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. Under certain conditions, Analytics, Visibility, and Reporting daemon (AVRD) may generate a core file and restart on the BIG-IP system when processing requests sent from mobile devices. A remote attacker can initiate a denial-of-service (DoS) attack on the AVRD process on the BIG-IP system from a mobile device.
This vulnerability occurs when all of the following conditions are met:
- Mobile SDK is licensed and enabled.
- An app using Mobile SDK on certain mobile devices sends a request to a virtual server with a Bot Defense profile.
- The AVRD process sends the statistics to a BIG-IQ system or any external log server.
Remediation
Install update from vendor's website.