Back to search
CVE-2020-5906
Published: Jul 1, 2020
Modified: Aug 4, 2024
PUBLISHED
Description
In versions 13.1.0-13.1.3.3, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, the BIG-IP system does not properly enforce the access controls for the scp.blacklist files. This allows Admin and Resource Admin users with Secure Copy (SCP) protocol access to read and overwrite blacklisted files via SCP.
| Vendor | Product | Versions |
|---|---|---|
n/a | BIG-IP | affected 13.1.0-13.1.3.3, 12.1.0-12.1.5.2, 11.6.1-11.6.5.2 |
References
https://support.f5.com/csp/article/K82518062
x_refsource_MISC
VU#290915
third-party-advisory
x_refsource_CERT-VN
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now