Memory leak in F5 Networks products - CVE-2020-27725
Published: December 17, 2020
Vulnerability details
The vulnerability exists due memory leak in zxfrd process when listing DNS zones. A remote user with access to TMSH, iControl or SNMP can force the application to leak memory and perform denial of service attack.
This vulnerability affects only BIG-IP systems that are provisioned with BIG-IP DNS or BIG-IP GTM and at least one DNS zone.
Affected software
BIG-IP Link Controller
BIG-IP DNS
How to mitigate CVE-2020-27725
BIG-IP Link Controller - addressed in versions 13.1.3.5, 14.1.3.1, 15.1.1
BIG-IP DNS - addressed in versions 13.1.3.5, 14.1.3.1, 15.1.1