Improper validation of integrity check value in BIG-IP - CVE-2020-5851
Published: January 14, 2020
Vulnerability identifier: #VU24238
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-5851
CWE-ID: CWE-354
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows an attacker to hide malicious activity.
The Trusted Platform Module (TPM) on the BIG-IP iSeries platforms (i850, i2000, i4000, i5000, i7000, i10000, i11000, i15000) and the VIPRION B4450 blades fails to function properly and is unable to detect any potential security compromise of the affected systems.
Affected software
BIG-IP
How to mitigate CVE-2020-5851
This vulnerability affects only the following items: these
engineering hotfixes based on BIG-IP 14.1.0.2; BIG-IP iSeries platforms;
and VIPRION B4450 blades.