
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-27727 affects BIG-IP versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, and 13.1.0-13.1.3.4. The vulnerability was discovered in 2020 and involves insufficient input validation when an authenticated administrative user installs RPMs using the iAppsLX REST installer (NVD).
The vulnerability stems from insufficient validation of user input during RPM installation through the iAppsLX REST installer. The CVSS v3.1 base score is 4.9 (Medium) with the vector string CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N. The vulnerability is classified under CWE-20 (Improper Input Validation) (NVD).
When exploited, this vulnerability allows an authenticated administrative user to gain read access to the filesystem on the BIG-IP system (CVE).
The vulnerability requires an authenticated administrative user account to exploit, as it is specifically related to the RPM installation process through the iAppsLX REST installer. The attack complexity is considered low, but privileged access is required (NVD).
F5 Networks has released patches for affected versions. Users should upgrade to versions newer than 16.0.0.1, 15.1.0.5, 14.1.3, or 13.1.3.4 depending on their installed version (Vendor Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."