5.5

CVE-2020-5898

In versions 7.1.5-7.1.9, BIG-IP Edge Client Windows Stonewall driver does not sanitize the pointer received from the userland. A local user on the Windows client system can send crafted DeviceIoControl requests to \\.\urvpndrv device causing the Windows kernel to crash.

Data is provided by the National Vulnerability Database (NVD)
F5Big-ip Access Policy Manager Version >= 11.6.1 <= 11.6.5.1
F5Big-ip Access Policy Manager Version >= 12.1.0 <= 12.1.5.1
F5Big-ip Access Policy Manager Version >= 13.1.0 <= 13.1.3.3
F5Big-ip Access Policy Manager Version >= 14.1.0 <= 14.1.2.5
F5Big-ip Access Policy Manager Version >= 15.0.0 <= 15.1.0.3
F5Big-ip Access Policy Manager Client Version >= 7.1.5 <= 7.1.9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.07% 0.176
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 4.9 3.9 6.9
AV:L/AC:L/Au:N/C:N/I:N/A:C