Resource management error in BIG-IP GTM and BIG-IP DNS - CVE-2020-27721
Published: December 17, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper management of internal resources within the BIG-IP DNS system.
This can occur under the following conditions:
- You configure connection rate limiting by either source or destination address for a BIG-IP LTM virtual server.
- The configured connection rate limit is exceeded on the BIG-IP LTM
virtual server (or Pool Member or Node), and the status of the virtual
server on the Configuration utility becomes yellow.
A remote attacker can send specially crafted data to the service and perform a denial of service (DoS) attack.
Affected software
BIG-IP DNS
How to mitigate CVE-2020-27721
BIG-IP DNS - addressed in versions 14.1.3.1, 15.1.2, 16.0.1