CVE-2020-5851

MEDIUM

F5 F5 BIG-IP - TPM System Integrity Check Bypass

Title source: llm
STIX 2.1

Description

On impacted versions and platforms the Trusted Platform Module (TPM) system integrity check cannot detect modifications to specific system components. This issue only impacts specific engineering hotfixes and platforms. NOTE: This vulnerability does not affect any of the BIG-IP major, minor or maintenance releases you obtained from downloads.f5.com. The affected Engineering Hotfix builds are as follows: Hotfix-BIGIP-14.1.0.2.0.45.4-ENG Hotfix-BIGIP-14.1.0.2.0.62.4-ENG

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://support.f5.com/csp/article/K91171450

Scores

CVSS v3 4.6
EPSS 0.0021
EPSS Percentile 42.6%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

Status published
Products (26)
f5/big-ip_access_policy_manager 14.1.0.2.0.45.4
f5/big-ip_access_policy_manager 14.1.0.2.0.62.4
f5/big-ip_advanced_firewall_manager 14.1.0.2.0.45.4
f5/big-ip_advanced_firewall_manager 14.1.0.2.0.62.4
f5/big-ip_analytics 14.1.0.2.0.45.4
f5/big-ip_analytics 14.1.0.2.0.62.4
f5/big-ip_application_acceleration_manager 14.1.0.2.0.45.4
f5/big-ip_application_acceleration_manager 14.1.0.2.0.62.4
f5/big-ip_application_security_manager 14.1.0.2.0.45.4
f5/big-ip_application_security_manager 14.1.0.2.0.62.4
... and 16 more
Published Jan 14, 2020
Tracked Since Feb 18, 2026