CVE-2020-5915:Stored XSS vulnerability in BIG-IP TMUI when systems are configured in a device trust

splash
Back

Description Preview

In BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, an undisclosed TMUI (Traffic Management User Interface) page contains a vulnerability which allows a stored cross-site scripting (XSS) attack when BIG-IP systems are setup in a device trust configuration. This vulnerability could potentially allow an attacker to execute malicious code in the context of the user's browser, potentially leading to credential theft, session hijacking, or other client-side attacks.

Overview

This vulnerability (CVE-2020-5915) is a stored cross-site scripting (CWE-79) issue affecting the Traffic Management User Interface (TMUI) of F5 BIG-IP systems. The vulnerability specifically manifests when BIG-IP systems are configured in a device trust relationship. An attacker with access to the vulnerable page could potentially inject malicious scripts that would be stored on the server and later executed in the browsers of administrators or other users accessing the affected page. The vulnerability impacts multiple versions of BIG-IP across several release branches, indicating a widespread issue that requires immediate attention from system administrators.

Remediation

To remediate this vulnerability, F5 recommends upgrading to one of the following fixed versions:

  • 15.1.0.5 or later
  • 15.0.1.4 or later
  • 14.1.2.4 or later
  • 13.1.3.4 or later
  • 12.1.5.2 or later
  • 11.6.5.2 or later

If upgrading is not immediately possible, administrators should limit access to the TMUI interface to trusted networks and users only. Additionally, implementing network segmentation and restricting administrative access to the management interface can help mitigate the risk. For detailed patching instructions and additional mitigation strategies, consult the F5 security advisory at https://support.f5.com/csp/article/K57214921.

References

  1. F5 Security Advisory: https://support.f5.com/csp/article/K57214921
  2. MITRE CWE-79 (Cross-site Scripting): https://cwe.mitre.org/data/definitions/79.html
  3. CVE-2020-5915 in the National Vulnerability Database: https://nvd.nist.gov/vuln/detail/CVE-2020-5915

Industry ExposureMost to least
This section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.

  1. Finance and Insurance
    Finance and Insurance
  2. Management of Companies & Enterprises
    Management of Companies & Enterprises
  3. Manufacturing
    Manufacturing
  4. Professional, Scientific, & Technical Services
    Professional, Scientific, & Technical Services
  5. Accommodation & Food Services
    Accommodation & Food Services
  6. Administrative, Support, Waste Management & Remediation Services
    Administrative, Support, Waste Management & Remediation Services
  7. Agriculture, Forestry Fishing & Hunting
    Agriculture, Forestry Fishing & Hunting
  8. Arts, Entertainment & Recreation
    Arts, Entertainment & Recreation
  9. Construction
    Construction
  10. Educational Services
    Educational Services
  11. Health Care & Social Assistance
    Health Care & Social Assistance
  12. Information
    Information
  13. Mining
    Mining
  14. Other Services (except Public Administration)
    Other Services (except Public Administration)
  15. Public Administration
    Public Administration
  16. Real Estate Rental & Leasing
    Real Estate Rental & Leasing
  17. Retail Trade
    Retail Trade
  18. Transportation & Warehousing
    Transportation & Warehousing
  19. Utilities
    Utilities
  20. Wholesale Trade
    Wholesale Trade

Focus on What Matters

  1. See Everything.
  2. Identify True Risk.
  3. Proactively Mitigate Threats.

Let's talk!

background