Improper Authentication in APM Clients and BIG-IP APM - CVE-2020-5855
Published: February 6, 2020
Vulnerability details
The vulnerability allows a local attacker to bypass authentication process.
The vulnerability exists due to an error when the Windows Logon Integration feature is configured for BIG-IP Edge Client. An attacker with physical access to an authorized user's machine can bypass authentication to gain unauthorized access to internal resources or compromise the availability of the resources.
Affected software
BIG-IP APM