CVE-2020-5923 describes a medium-severity vulnerability affecting multiple versions of F5 BIG-IP and BIG-IQ products, allowing a bypass of Self-IP port-lockdown via IPv6 link-local addresses. This network-adjacent vulnerability (AV:A) is of low complexity (AC:L) and requires no privileges (PR:N) or user interaction (UI:N), potentially leading to limited confidentiality and integrity impacts (C:L/I:L/A:N). While the EPSS score is low, indicating a minimal likelihood of exploitation, there is no known exploit code available in common repositories like Metasploit or ExploitDB. Furthermore, there is no evidence of active exploitation, media coverage, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 11.6.1, < 11.6.5.2CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* | ||
>= 12.1.0, < 12.1.5.2CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* | ||
>= 13.1.0, < 13.1.3.4CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* | ||
>= 14.1.0, < 14.1.2.7CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* | ||
>= 15.0.0, < 15.1.0.5CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.