CVE-2020-5904
F5 BIG-IP Advanced Firewall Manager vulnerability analysis and mitigation

Overview

A cross-site request forgery (CSRF) vulnerability was discovered in the Traffic Management User Interface (TMUI), also known as the Configuration utility, of F5 BIG-IP systems. The vulnerability affects BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, and 12.1.0-12.1.5.1. This security issue was assigned CVE-2020-5904 and was disclosed on July 1, 2020 (NVD, CERT VN).

Technical details

The vulnerability exists in an undisclosed page of the TMUI interface where the application fails to properly implement CSRF protections. This security flaw is part of a broader set of vulnerabilities discovered in F5 BIG-IP devices, which include issues related to improper input neutralization and access control enforcement (CERT VN).

Impact

The CSRF vulnerability could allow attackers to perform unauthorized actions on behalf of authenticated users of the TMUI interface. This could potentially lead to configuration changes or other unauthorized actions on the BIG-IP system (CERT VN).

Exploitability

The vulnerability requires access to the TMUI interface to be exploited. F5 recommends that the TMUI web interface should only be accessible from a secure or out-of-band network and not directly from the Internet (CERT VN).

Mitigation and workarounds

F5 has released patches for the affected versions of BIG-IP. Organizations are strongly advised to upgrade to the latest secure and stable software provided by F5. The updates are essential even if the TMUI is not accessible over the Internet, as they reduce the risk of compromise through CSRF attacks. Additionally, blocking or disabling access to TMUI from untrusted networks is highly recommended as a temporary mitigation measure (CERT VN).

Additional resources


SourceThis report was generated using AI

Related F5 BIG-IP Advanced Firewall Manager vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-41433HIGH8.7
  • F5 BIG-IP Advanced Firewall Manager logoF5 BIG-IP Advanced Firewall Manager
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NoYesMay 07, 2025
CVE-2025-41431HIGH8.7
  • F5 BIG-IP Advanced Firewall Manager logoF5 BIG-IP Advanced Firewall Manager
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NoYesMay 07, 2025
CVE-2025-41414HIGH8.7
  • F5 BIG-IP Advanced Firewall Manager logoF5 BIG-IP Advanced Firewall Manager
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NoYesMay 07, 2025
CVE-2025-41399HIGH8.7
  • F5 BIG-IP Advanced Firewall Manager logoF5 BIG-IP Advanced Firewall Manager
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NoYesMay 07, 2025
CVE-2025-54500MEDIUM6.9
  • F5 BIG-IP Advanced Firewall Manager logoF5 BIG-IP Advanced Firewall Manager
  • cpe:2.3:a:f5:big-ip_next_central_manager
NoYesAug 13, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management