CVE-2020-5893: F5 BIG-IP Access Policy Manager

Low severity, CVSS 3.7. EPSS: 0.6% chance of exploitation in the next 30 days.

In versions 7.1.5-7.1.8, when a user connects to a VPN using BIG-IP Edge Client over an unsecure network, BIG-IP Edge Client responds to authentication requests over HTTP while sending probes for captive portal detection.

Affected products

  • F5 BIG-IP Access Policy Manager: from 11.6.1, up to and including 11.6.5; from 12.1.0, up to and including 12.1.5; from 13.1.0, up to and including 13.1.3; from 14.0.0, up to and including 14.1.2; from 15.0.0, up to and including 15.1.0
  • F5 BIG-IP Access Policy Manager Client: from 7.1.5, before 7.1.9 (fixed in 7.1.9)

Published 2020-04-30. Last modified 2026-06-17.