CVE-2020-5871
F5 BIG-IP Advanced Firewall Manager vulnerability analysis and mitigation

Overview

A denial of service (DoS) vulnerability was discovered in F5 BIG-IP versions 14.1.0-14.1.2.3. The vulnerability occurs when undisclosed requests are sent to BIG-IP HTTP/2 virtual servers, particularly when ciphers that have been blacklisted by the HTTP/2 RFC are used on backend servers. This is specifically a data-plane issue with no control-plane exposure (CVE Mitre, NVD).

Technical details

The vulnerability affects BIG-IP versions 14.1.0 through 14.1.2.3. The issue specifically involves the HTTP/2 virtual servers and their interaction with blacklisted ciphers as defined in the HTTP/2 RFC. The vulnerability is limited to the data-plane, meaning it affects traffic processing rather than device management functions (CVE Mitre).

Impact

When successfully exploited, this vulnerability can lead to a denial of service condition on affected BIG-IP systems, potentially disrupting the availability of services running on HTTP/2 virtual servers (NVD).

Exploitability

The vulnerability can be triggered by sending specific undisclosed requests to BIG-IP HTTP/2 virtual servers when certain blacklisted ciphers are in use on backend servers (CVE Mitre).

Mitigation and workarounds

The vulnerability has been addressed in versions after 14.1.2.3. Organizations running affected versions should upgrade to a patched version to mitigate this vulnerability (CERT-FR).

Additional resources


SourceThis report was generated using AI

Related F5 BIG-IP Advanced Firewall Manager vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-41433HIGH8.7
  • F5 BIG-IP Advanced Firewall Manager logoF5 BIG-IP Advanced Firewall Manager
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NoYesMay 07, 2025
CVE-2025-41431HIGH8.7
  • F5 BIG-IP Advanced Firewall Manager logoF5 BIG-IP Advanced Firewall Manager
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NoYesMay 07, 2025
CVE-2025-41414HIGH8.7
  • F5 BIG-IP Advanced Firewall Manager logoF5 BIG-IP Advanced Firewall Manager
  • cpe:2.3:a:f5:big-ip_application_security_manager
NoYesMay 07, 2025
CVE-2025-41399HIGH8.7
  • F5 BIG-IP Advanced Firewall Manager logoF5 BIG-IP Advanced Firewall Manager
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NoYesMay 07, 2025
CVE-2025-54500MEDIUM6.9
  • F5 BIG-IP Advanced Firewall Manager logoF5 BIG-IP Advanced Firewall Manager
  • cpe:2.3:a:f5:big-ip_application_security_manager
NoYesAug 13, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management