#VU26459 Man-in-the-Middle (MitM) attack in F5 Networks products - CVE-2020-5860
Published: March 30, 2020
BIG-IQ Centralized Management
BIG-IP
BIG-IP LTM
BIG-IP AFM
BIG-IP Analytics
BIG-IP APM
BIG-IP ASM
BIG-IP FPS
BIG-IP GTM
BIG-IP PEM
BIG-IP AAM
BIG-IP DNS
BIG-IP Link Controller
F5 Networks
Description
The vulnerability allows a remote attacker to perform a man-in-the-middle (MitM) attack.
The vulnerability exists in a High Availability (HA) network failover in Device Service Cluster (DSC) due to the failover service does not require a strong form of authentication and HA network failover traffic is not encrypted by Transport Layer Security (TLS). A remote attacker can perform a man-in-the-middle attack to access the unencrypted HA network failover traffic.