Input validation error in BIG-IP ASM and BIG-IP Advanced WAF - CVE-2020-27728
Published: December 17, 2020
BIG-IP ASM
BIG-IP Advanced WAF
F5 Networks
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. Under certain conditions, Analytics, Visibility, and Reporting daemon (AVRD) may generate a core file and restart on the BIG-IP system when processing requests sent from mobile devices. A remote attacker can initiate a denial-of-service (DoS) attack on the AVRD process on the BIG-IP system from a mobile device.
This vulnerability occurs when all of the following conditions are met:
- Mobile SDK is licensed and enabled.
- An app using Mobile SDK on certain mobile devices sends a request to a virtual server with a Bot Defense profile.
- The AVRD process sends the statistics to a BIG-IQ system or any external log server.