Denial of service in Node.js component in multiple F5 BIG-IP products



Published: 2021-02-24
Risk Medium
Patch available NO
Number of vulnerabilities 1
CVE-ID CVE-2020-8277
CWE-ID CWE-399
Exploitation vector Network
Public exploit Public exploit code for vulnerability #1 is available.
Vulnerable software
Subscribe
BIG-IP SSLO
Hardware solutions / Firmware

BIG-IP DDHD
Hardware solutions / Firmware

BIG-IP
Hardware solutions / Firmware

BIG-IP PEM
Hardware solutions / Security hardware applicances

BIG-IP GTM
Hardware solutions / Security hardware applicances

BIG-IP FPS
Hardware solutions / Security hardware applicances

BIG-IP ASM
Hardware solutions / Security hardware applicances

BIG-IP APM
Hardware solutions / Security hardware applicances

BIG-IP Analytics
Hardware solutions / Security hardware applicances

BIG-IP AFM
Hardware solutions / Security hardware applicances

BIG-IP LTM
Hardware solutions / Security hardware applicances

BIG-IP Link Controller
Hardware solutions / Routers & switches, VoIP, GSM, etc

BIG-IP DNS
Hardware solutions / Routers & switches, VoIP, GSM, etc

BIG-IP AAM
Hardware solutions / Routers & switches, VoIP, GSM, etc

BIG-IP Advanced WAF
Client/Desktop applications / Antivirus software/Personal firewalls

BIG-IQ Centralized Management
Server applications / Remote management servers, RDP, SSH

Vendor F5 Networks, Inc.

Security Bulletin

This security bulletin contains one medium risk vulnerability.

1) Resource management error

EUVDB-ID: #VU48569

Risk: Medium

CVSSv3.1:

CVE-ID: CVE-2020-8277

CWE-ID: CWE-399 - Resource Management Errors

Exploit availability: Yes

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper management of internal resources within the application when processing a large number of DNS responses. A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a denial of service condition.

Mitigation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

Vulnerable software versions

BIG-IP SSLO: 11.6.1 - 16.0.1.1

BIG-IP PEM: 11.6.1 - 16.0.1.1

BIG-IP Link Controller: 11.6.1 - 16.0.1.1

BIG-IP GTM: 11.6.1 - 16.0.1.1

BIG-IP FPS: 11.6.1 - 16.0.1.1

BIG-IP DNS: 11.6.1 - 16.0.1.1

BIG-IP DDHD: 11.6.1 - 16.0.1.1

BIG-IP ASM: 11.6.1 - 16.0.1.1

BIG-IP APM: 11.6.1 - 16.0.1.1

BIG-IP Analytics: 11.6.1 - 16.0.1.1

BIG-IP AFM: 11.6.1 - 16.0.1.1

BIG-IP Advanced WAF: 11.6.1 - 16.0.1.1

BIG-IP AAM: 11.6.1 - 16.0.1.1

BIG-IP LTM: 11.6.1 - 16.0.1.1

BIG-IP: 11.6.1 - 16.0.1.1

BIG-IQ Centralized Management: 7.1.0


CPE2.3 External links

http://support.f5.com/csp/article/K07944249

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?



###SIDEBAR###