CVE-2020-27713: F5 BIG-IP Advanced Firewall Manager

High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.

In certain configurations on version 13.1.3.4, when a BIG-IP AFM HTTP security profile is applied to a virtual server and the BIG-IP system receives a request with specific characteristics, the connection is reset and the Traffic Management Microkernel (TMM) leaks memory.

Affected products

  • F5 BIG-IP Advanced Firewall Manager: version 13.1.3.4 only

Published 2020-12-11. Last modified 2026-06-17.