In versions 13.1.0-13.1.3.3, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, the BIG-IP system does not properly enforce the access controls for the scp.blacklist files. This allows Admin and Resource Admin users with Secure Copy (SCP) protocol access to read and overwrite blacklisted files via SCP.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: f5

Published: 2020-07-01T14:33:20

Updated: 2024-08-04T08:47:40.900Z

Reserved: 2020-01-06T00:00:00

Link: CVE-2020-5906

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-07-01T15:15:15.673

Modified: 2023-01-27T16:38:01.903

Link: CVE-2020-5906

cve-icon Redhat

No data.