Перейти к содержимому
CodeAuditAgent

CVE-2026-63020

A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages Impact: An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a spoofed error message in the victim's BIG-IP Configuration utility web browser session. This is a control plane issue; there is no data plane exposure. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

НизкийCWE-451 Все CVE

Слабость

A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages Impact: An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a spoofed error message in the victim's BIG-IP Configuration utility web browser session. This is a control plane issue; there is no data plane exposure. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Затронутые продукты

  • f5 big-ip_access_policy_manager
  • f5 big-ip_advanced_firewall_manager
  • f5 big-ip_advanced_web_application_firewall
  • f5 big-ip_analytics
  • f5 big-ip_application_acceleration_manager
  • f5 big-ip_application_security_manager
  • f5 big-ip_application_visibility_and_reporting
  • f5 big-ip_automation_toolchain

Источники

Найдите уязвимость раньше атакующего.

Войдите через GitHub и запустите первый аудит меньше чем за минуту. Для бесплатного тарифа банковская карта не нужна.