#VU27516 Missing Encryption of Sensitive Data in BIG-IP ASM - CVE-2020-5879
Published: May 5, 2020
BIG-IP ASM
F5 Networks
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the BIG-IP system, under certain configurations, sends data plane traffic to back-end servers unencrypted, even when a Server SSL profile is applied. A remote attacker can gain unauthorized access to sensitive information on the system.
The requests affected by this vulnerability are processed by a virtual server associated with a DoS profile that has a CAPTCHA challenge configured.