
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-27717 is a vulnerability affecting BIG-IP DNS systems across multiple versions (16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, and 12.1.0-12.1.5.2). The vulnerability was discovered and disclosed in October 2020, with the initial NVD analysis published on December 28, 2020 (NVD).
The vulnerability involves an undisclosed series of DNS requests that can cause the Traffic Management Microkernel (TMM) to restart and generate a core file. The vulnerability has been assigned a CVSS v3.1 base score of 7.5 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, indicating network accessibility, low attack complexity, and no required privileges or user interaction (NVD).
The primary impact of this vulnerability is on system availability, as successful exploitation can cause the TMM service to restart, potentially leading to service disruption. The CVSS scoring indicates high impact on availability while maintaining no direct impact on confidentiality or integrity (NVD).
The vulnerability is network-accessible (AV:N) with low attack complexity (AC:L), requiring no privileges (PR:N) or user interaction (UI:N). This combination of factors makes the vulnerability relatively straightforward to exploit if left unpatched (NVD).
F5 Networks has released patches for affected versions. Users should upgrade to versions 13.1.3.5, 14.1.3.1, 15.1.1, or 16.0.1 depending on their current version track (F5 Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."