CVE-2020-5903
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, a Cross-Site Scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility.
- Affected products
- Big-Ip
- f5 Big-ip Access Policy Manager
- ≤ 12.1.5, 13.1.3, 14.1.2, 15.1.0
- f5 Big-ip Advanced Firewall Manager
- ≤ 12.1.5, 13.1.3, 14.1.2, 15.1.0
- f5 Big-ip Analytics
- ≤ 12.1.5, 13.1.3, 14.1.2, 15.1.0
- f5 Big-ip Application Acceleration Manager
- ≤ 12.1.5, 13.1.3, 14.1.2, 15.1.0
- f5 Big-ip Application Security Manager
- ≤ 12.1.5, 13.1.3, 14.1.2, 15.1.0
- f5 Big-ip Domain Name System
- ≤ 12.1.5, 13.1.3, 14.1.2, 15.1.0
- CVSS 3.1
- 6.1 MEDIUM
- EPSS
- 2.0% (79th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2020-07-01
CVE-2020-5903 at NVD
2 known exploits for CVE-2020-5903
Proof-of-concept code and exploit modules indexed by Sploitus