
Cloud Vulnerability DB
A community-led vulnerabilities database
A cross-site request forgery (CSRF) vulnerability was discovered in the Traffic Management User Interface (TMUI), also known as the Configuration utility, of F5 BIG-IP systems. The vulnerability affects BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, and 12.1.0-12.1.5.1. This security issue was assigned CVE-2020-5904 and was disclosed on July 1, 2020 (NVD, CERT VN).
The vulnerability exists in an undisclosed page of the TMUI interface where the application fails to properly implement CSRF protections. This security flaw is part of a broader set of vulnerabilities discovered in F5 BIG-IP devices, which include issues related to improper input neutralization and access control enforcement (CERT VN).
The CSRF vulnerability could allow attackers to perform unauthorized actions on behalf of authenticated users of the TMUI interface. This could potentially lead to configuration changes or other unauthorized actions on the BIG-IP system (CERT VN).
The vulnerability requires access to the TMUI interface to be exploited. F5 recommends that the TMUI web interface should only be accessible from a secure or out-of-band network and not directly from the Internet (CERT VN).
F5 has released patches for the affected versions of BIG-IP. Organizations are strongly advised to upgrade to the latest secure and stable software provided by F5. The updates are essential even if the TMUI is not accessible over the Internet, as they reduce the risk of compromise through CSRF attacks. Additionally, blocking or disabling access to TMUI from untrusted networks is highly recommended as a temporary mitigation measure (CERT VN).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."