CISA KEV · catalog date Nov 3, 2021 · first observed Jul 19, 2026
Evidence dossier
CVE-2020-5902
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as…
Exploited in the wild (CISA KEV since Nov 3, 2021). NVD reports CVSS 3.1 9.8. EPSS estimates 100.0% exploit likelihood as of Jul 18, 2026.
As of Aug 27, 2026
Normalized restatement
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulnerability in undisclosed pages.
- State
- PUBLISHED
- Published
- Jul 1, 2020
- Updated
- Oct 21, 2025
- Evidence coverage
- 99%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAf5Original evidence ↗
Record text: In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulnerability in undisclosed pages.
Inspect raw assertion
- Field
container- Value
- In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulnerability in undisclosed pages.
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 100% probability · 100th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.999990000000; percentile 1.000000000000
FIRST EPSS · score date Jul 18, 2026 · 100th percentile · first observed Jul 19, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulnerability in undisclosed pages.
Inspect raw assertion
- Field
container- Value
- In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulnerability in undisclosed pages.
F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution Vulnerability
100% probability · 100th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.999990000000; percentile 1.000000000000
Applicability
Cited product scope
Grouped from 1 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
15 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, 11.6.1-11.6.5.1"}]product-fe8f45eed4bb3ac6e69f6f6fbf87e9e25862951e870386e176dca756ebfdb2cbLinked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 11.6.1; through excluding 11.6.5.2
- Match ID
bb236652-bd60-4fef-9d59-8b49fb3a7655
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 2
- Logic
- OR
- Version bounds
- from including 13.1.0; through excluding 13.1.3.4
- Match ID
592327aa-bcc4-4cd0-82c6-ea739f049e82
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 3
- Logic
- OR
- Version bounds
- from including 14.1.0; through excluding 14.1.2.6
- Match ID
3a49f18e-2004-4bdb-ba3f-93c52b23cca9
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 5
- Logic
- OR
- Version bounds
- from including 15.1.0; through excluding 15.1.0.4
- Match ID
11f32785-49da-4c57-ad28-bc630e55222a
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- from including 12.1.0; through excluding 12.1.5.2
- Match ID
ee0532fa-7b7b-46b3-ab10-0920034a7e43
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 4
- Logic
- OR
- Version bounds
- from including 15.0.0; through including 15.0.1.4
- Match ID
65c2e51d-76ff-4604-b9a6-1eb48aaf1ca6
product-c611bfdeac48cac2141d0aebba0e7ba6ff1c599d72cfe95a76f1db1b7fe68b36Linked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 8
- Logic
- OR
- Version bounds
- from including 13.1.0; through excluding 13.1.3.4
- Match ID
3dd78d19-d17e-45ec-98c7-74d086ae68aa
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 7
- Logic
- OR
- Version bounds
- from including 12.1.0; through excluding 12.1.5.2
- Match ID
3b3dce49-c37d-4951-ab57-7cddeba1c1e5
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 10
- Logic
- OR
- Version bounds
- from including 15.0.0; through excluding 15.0.1.4
- Match ID
5b59e16d-7645-492a-9c1d-a8724ffca28f
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 11
- Logic
- OR
- Version bounds
- from including 15.1.0; through excluding 15.1.0.4
- Match ID
efb71683-c715-41db-a42e-4269d26d5dd3
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 9
- Logic
- OR
- Version bounds
- from including 14.1.0; through excluding 14.1.2.6
- Match ID
0cdd8550-e2bc-44b4-857c-706d2dc769f0
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 6
- Logic
- OR
- Version bounds
- from including 11.6.1; through excluding 11.6.5.2
- Match ID
adb2b518-f813-4b11-bbf5-0bfb2979a6b8
product-3159127811fadcfbf55e58810b397c704a5ecb216e89a6fccc26cab6944674c7Linked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 13
- Logic
- OR
- Version bounds
- from including 12.1.0; through excluding 12.1.5.2
- Match ID
694c630b-5342-4c6c-a0fa-050b9c76936d
cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 12
- Logic
- OR
- Version bounds
- from including 11.6.1; through excluding 11.6.5.2
- Match ID
e64263b7-7be1-472e-9130-7bc8f2932683
cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 16
- Logic
- OR
- Version bounds
- from including 15.0.0; through excluding 15.0.1.4
- Match ID
7fbf20c1-5b3c-4dc0-b6f7-4db0205bf2b0
cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 14
- Logic
- OR
- Version bounds
- from including 13.1.0; through excluding 13.1.3.4
- Match ID
ec400989-fe65-4dec-b9dd-7bef6eb72dc0
cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 17
- Logic
- OR
- Version bounds
- from including 15.1.0; through excluding 15.1.0.4
- Match ID
b8434935-ce50-4ce7-ba17-6966e71bc9fd
cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 15
- Logic
- OR
- Version bounds
- from including 14.1.0; through excluding 14.1.2.6
- Match ID
708fd0a9-5167-45b5-80a1-85f105365c98
product-000cb533806b78ef860fa6bff163646e9d5756ef6c2d4d7d222692c4cd4c943fLinked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 18
- Logic
- OR
- Version bounds
- from including 11.6.1; through excluding 11.6.5.2
- Match ID
31e16a1b-e305-4390-976c-5f33a82ef396
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 23
- Logic
- OR
- Version bounds
- from including 15.1.0; through excluding 15.1.0.4
- Match ID
b8e7820d-a574-41c8-a602-05a825f26726
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 22
- Logic
- OR
- Version bounds
- from including 15.0.0; through excluding 15.0.1.4
- Match ID
92f370c2-3c5a-416d-83c1-a4f84866e958
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 20
- Logic
- OR
- Version bounds
- from including 13.1.0; through excluding 13.1.3.4
- Match ID
f1c551c9-169c-450e-965a-4f9f3e2c785b
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 19
- Logic
- OR
- Version bounds
- from including 12.1.0; through excluding 12.1.5.2
- Match ID
0c3e75cb-c764-4868-8459-1fac03506ee8
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 21
- Logic
- OR
- Version bounds
- from including 14.1.0; through excluding 14.1.2.6
- Match ID
32e6595b-27f1-4298-9b72-5618a5a0605a
product-bcf09b1e7f256f8ae475f16dc9eb0c89893ad01b1d9c94b66d17ac875578a078Linked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 29
- Logic
- OR
- Version bounds
- from including 15.1.0; through excluding 15.1.0.4
- Match ID
a7b37cd3-4b52-4761-9bec-5d4cc57783b8
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 26
- Logic
- OR
- Version bounds
- from including 13.1.0; through excluding 13.1.3.4
- Match ID
b547f46f-5563-4e7f-8b69-3d25c6c58521
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 24
- Logic
- OR
- Version bounds
- from including 11.6.1; through excluding 11.6.5.2
- Match ID
0fb118fb-2efb-4f17-b6e1-fc4b46b9c265
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 28
- Logic
- OR
- Version bounds
- from including 15.0.0; through excluding 15.0.1.4
- Match ID
997d12f1-098d-4c42-a6a2-b4f59ac78f0f
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 27
- Logic
- OR
- Version bounds
- from including 14.1.0; through excluding 14.1.2.6
- Match ID
6317dd02-5fc5-4476-8f63-8a7915440f94
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 25
- Logic
- OR
- Version bounds
- from including 12.1.0; through excluding 12.1.5.2
- Match ID
5d3f7911-fb00-4612-9109-9e7a407bc7b7
product-ba5b29ee89c2340743c5ed2999e757bf44af0086b8b527afdbbe3f8a626803daLinked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 30
- Logic
- OR
- Version bounds
- from including 11.6.1; through excluding 11.6.5.2
- Match ID
8999f566-9884-4caa-bed7-8cf72f11e6f8
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 35
- Logic
- OR
- Version bounds
- from including 15.1.0; through excluding 15.1.0.4
- Match ID
a4c4b36f-aba3-4c9c-be94-389a91185ce5
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 33
- Logic
- OR
- Version bounds
- from including 14.1.0; through excluding 14.1.2.6
- Match ID
ba19452d-9c3d-41fb-8606-51f90126b2a0
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 32
- Logic
- OR
- Version bounds
- from including 13.1.0; through excluding 13.1.3.4
- Match ID
4aee0b76-3f8e-420a-9589-bf3fdb942deb
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 31
- Logic
- OR
- Version bounds
- from including 12.1.0; through excluding 12.1.5.2
- Match ID
91bf72a9-eb50-4315-b956-5926967dcc46
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 34
- Logic
- OR
- Version bounds
- from including 15.0.0; through excluding 15.0.1.4
- Match ID
e6c4b56f-d022-4268-9d78-6e4d12ae9215
product-f87c7b9b64c86afcc0c48220bda1bc92543beefff7155621fe458a2627cfe653Linked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 39
- Logic
- OR
- Version bounds
- from including 14.1.0; through excluding 14.1.2.6
- Match ID
fe999923-5893-44d4-9212-e94990a3f1a7
cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 36
- Logic
- OR
- Version bounds
- from including 11.6.1; through excluding 11.6.5.2
- Match ID
ec8b0f64-d0fc-4cc9-94ca-38a55043c529
cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 37
- Logic
- OR
- Version bounds
- from including 12.1.0; through excluding 12.1.5.2
- Match ID
39aecff0-3a86-45a4-ab7f-dcc3717e8e97
cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 41
- Logic
- OR
- Version bounds
- from including 15.1.0; through excluding 15.1.0.4
- Match ID
1e34f61c-1c60-4ba7-a282-c5b295a7241c
cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 38
- Logic
- OR
- Version bounds
- from including 13.1.0; through excluding 13.1.3.4
- Match ID
3f8b4719-b7c7-4383-b74b-119dd5f51773
cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 40
- Logic
- OR
- Version bounds
- from including 15.0.0; through excluding 15.0.1.4
- Match ID
62f2cbb9-c4fe-4065-8f13-e677e572f4b9
product-8f453bafc34e9c461b1290b73550569e7558e64398eede2e74d46d6cb72adae8Linked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 44
- Logic
- OR
- Version bounds
- from including 13.1.0; through excluding 13.1.3.4
- Match ID
c7917031-0735-483c-a8da-11430056d568
cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 43
- Logic
- OR
- Version bounds
- from including 12.1.0; through excluding 12.1.5.2
- Match ID
73ec8eda-669a-4750-934f-3b3fbf557080
cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 47
- Logic
- OR
- Version bounds
- from including 15.1.0; through excluding 15.1.0.4
- Match ID
0db7ee01-966a-40eb-8f49-afe22b1faf31
cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 42
- Logic
- OR
- Version bounds
- from including 11.6.1; through excluding 11.6.5.2
- Match ID
f997f6d8-d08d-4eb0-bea7-288aefd6f28c
cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 45
- Logic
- OR
- Version bounds
- from including 14.1.0; through excluding 14.1.2.6
- Match ID
357fd2b0-3437-4d26-9d84-fe1449e37a74
cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 46
- Logic
- OR
- Version bounds
- from including 15.0.0; through excluding 15.0.1.4
- Match ID
eafc0d83-7f64-44f2-a014-37de3caf846a
product-e23ab53fe98a6d7dc5b97fdacee007e8bb696cfe3231c6ccc001c53853c3209cLinked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 53
- Logic
- OR
- Version bounds
- from including 15.1.0; through excluding 15.1.0.4
- Match ID
3cd1518d-e884-4b38-96cb-2c02493352b3
cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 49
- Logic
- OR
- Version bounds
- from including 12.1.0; through excluding 12.1.5.2
- Match ID
a0581eef-98e6-4961-8178-ba2d7647f931
cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 50
- Logic
- OR
- Version bounds
- from including 13.1.0; through excluding 13.1.3.4
- Match ID
ffc5c221-ae58-4580-876a-e5fd7970a695
cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 52
- Logic
- OR
- Version bounds
- from including 15.0.0; through excluding 15.0.1.4
- Match ID
920bc3dd-a1d4-403b-83d2-00636c20ffc0
cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 48
- Logic
- OR
- Version bounds
- from including 11.6.1; through excluding 11.6.5.2
- Match ID
925da0b2-7570-4819-845c-c35e5b168f80
cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 51
- Logic
- OR
- Version bounds
- from including 14.1.0; through excluding 14.1.2.6
- Match ID
5746ae6e-9d1b-4275-a756-4ffbee9fc6d3
product-618e73be1c78cebd98c0451389a4bfe0fed7033b9a99c5dfef4ab081a1711fd0Linked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 55
- Logic
- OR
- Version bounds
- from including 12.1.0; through excluding 12.1.5.2
- Match ID
32773569-67fe-4f08-a613-e507fcdeacef
cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 58
- Logic
- OR
- Version bounds
- from including 15.0.0; through excluding 15.0.1.4
- Match ID
49c8be4a-ded6-451a-b6ee-ac95dd26f85a
cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 56
- Logic
- OR
- Version bounds
- from including 13.1.0; through excluding 13.1.3.4
- Match ID
463aa399-492a-4db6-bfd1-31725012ae8f
cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 59
- Logic
- OR
- Version bounds
- from including 15.1.0; through excluding 15.1.0.4
- Match ID
ab170091-1f18-46d7-8164-acc9b05954e3
cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 57
- Logic
- OR
- Version bounds
- from including 14.1.0; through excluding 14.1.2.6
- Match ID
a52b5ea8-31e5-4cdb-81fb-3ae8251f29cf
cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 54
- Logic
- OR
- Version bounds
- from including 11.6.1; through excluding 11.6.5.2
- Match ID
a4a036a0-5e0c-4e64-b88d-d1b61257896e
product-8754268b8c2cde0fe6aca92689e07534654bf0c32f504fdc7eabdc3dd51c0dabLinked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 61
- Logic
- OR
- Version bounds
- from including 12.1.0; through excluding 12.1.5.2
- Match ID
4494f771-4026-478c-8004-b162653dc80c
cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 63
- Logic
- OR
- Version bounds
- from including 14.1.0; through excluding 14.1.2.6
- Match ID
2b1ac241-fe68-4275-8992-7575aa8ad118
cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 65
- Logic
- OR
- Version bounds
- from including 15.1.0; through excluding 15.1.0.4
- Match ID
d30769c3-f8cb-491a-8e51-0147aa07dda4
cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 64
- Logic
- OR
- Version bounds
- from including 15.0.0; through excluding 15.0.1.4
- Match ID
dec0e30f-6550-4bc9-8da7-6bd495dbf415
cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 62
- Logic
- OR
- Version bounds
- from including 13.1.0; through excluding 13.1.3.4
- Match ID
98314370-e3c8-4cb5-9f48-57004eb96d8f
cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 60
- Logic
- OR
- Version bounds
- from including 11.6.1; through excluding 11.6.5.2
- Match ID
97ab336e-2a10-4508-9f20-db54d628355f
product-dfc8c075c3b90f711dd6c07c1d70e2c3507742bbcffef3651f2737a4133eeb81Linked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 68
- Logic
- OR
- Version bounds
- from including 13.1.0; through excluding 13.1.3.4
- Match ID
fbf128b7-874b-4e3a-b52f-1c2de34f64a9
cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 71
- Logic
- OR
- Version bounds
- from including 15.1.0; through excluding 15.1.0.4
- Match ID
abafae9b-aa80-4d3b-aa3a-4ed5c3be6113
cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 69
- Logic
- OR
- Version bounds
- from including 14.1.0; through excluding 14.1.2.6
- Match ID
29f4e502-d8d5-4719-986f-90bc08b3dc16
cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 66
- Logic
- OR
- Version bounds
- from including 11.6.1; through excluding 11.6.5.2
- Match ID
54d289f0-1896-4996-aedf-b299c6db8945
cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 67
- Logic
- OR
- Version bounds
- from including 12.1.0; through excluding 12.1.5.2
- Match ID
a97489dc-a5de-48ad-bba2-f9078070f53a
cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 70
- Logic
- OR
- Version bounds
- from including 15.0.0; through excluding 15.0.1.4
- Match ID
d5d90f4a-fa2a-412f-8591-d1ca6399ecad
product-b94ca11deae6f3dbdfe71c801d37911c9fd185c5bd3c37c804c67d15918d47d3Linked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 73
- Logic
- OR
- Version bounds
- from including 12.1.0; through excluding 12.1.5.2
- Match ID
1edb944b-df60-45af-ad60-33e9667e0d12
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 77
- Logic
- OR
- Version bounds
- from including 15.1.0; through excluding 15.1.0.4
- Match ID
7e314109-d770-4055-9248-2be25b0ef084
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 76
- Logic
- OR
- Version bounds
- from including 15.0.0; through excluding 15.0.1.4
- Match ID
bad2867d-d646-4b01-a383-6a47b51d059e
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 75
- Logic
- OR
- Version bounds
- from including 14.1.0; through excluding 14.1.2.6
- Match ID
67516a0b-7359-42de-b318-6979deefc229
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 74
- Logic
- OR
- Version bounds
- from including 13.1.0; through excluding 13.1.3.4
- Match ID
20c58940-c7a3-47a9-8c9e-7b652e4f4750
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 72
- Logic
- OR
- Version bounds
- from including 11.6.1; through excluding 11.6.5.2
- Match ID
78f7a30f-4455-420d-9254-e9910e16ec3f
product-cf4091ca4e2fda20d15e130d8a797ab0e11077ff758509d164c8e77b9177c404Linked exactInspect raw assertions
cpe:2.3:a:f5:ssl_orchestrator:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 78
- Logic
- OR
- Version bounds
- from including 11.6.1; through excluding 11.6.5.2
- Match ID
53f1f7bd-512d-46d4-a888-a2670deb1c4f
cpe:2.3:a:f5:ssl_orchestrator:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 81
- Logic
- OR
- Version bounds
- from including 14.1.0; through excluding 14.1.2.6
- Match ID
6b4bc535-7f99-45f4-9094-29b52deb8168
cpe:2.3:a:f5:ssl_orchestrator:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 83
- Logic
- OR
- Version bounds
- from including 15.1.0; through excluding 15.1.0.4
- Match ID
0f20f608-2930-41f2-a720-b8638395ff44
cpe:2.3:a:f5:ssl_orchestrator:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 82
- Logic
- OR
- Version bounds
- from including 15.0.0; through excluding 15.0.1.4
- Match ID
4f54a8ae-61f3-4f43-82bf-55842b56064a
cpe:2.3:a:f5:ssl_orchestrator:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 80
- Logic
- OR
- Version bounds
- from including 13.1.0; through excluding 13.1.3.4
- Match ID
57a7a47c-dbc5-4d1b-9c54-4a04c16bd904
cpe:2.3:a:f5:ssl_orchestrator:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 79
- Logic
- OR
- Version bounds
- from including 12.1.0; through excluding 12.1.5.2
- Match ID
ae483701-8cb3-4745-bd47-b022ebea2ca9
Affected-product evidence
Accepted scope and product mapping
14 canonical links · 1 source-reported links
vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-000cb533806b78ef860fa6bff163646e9d5756ef6c2d4d7d222692c4cd4c943f
- Source class
- Nvd cpe vulnerable target
- Assertions
- 6
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0034c5b2-fe49-4b08-a091-6d2dc9467a451503bd04-6e14-4171-9cdb-e5023e47941957d055f7-2b28-4c86-859f-abe958cff6636db96549-275a-42c5-8bdc-cbea03325618a6285808-4174-42cb-bfd4-bcefbf3dc456b87ecbc1-51dc-4b2b-be70-887a4902189dvendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-3159127811fadcfbf55e58810b397c704a5ecb216e89a6fccc26cab6944674c7
- Source class
- Nvd cpe vulnerable target
- Assertions
- 6
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
351ca2b2-2450-4361-8ef0-63567a96ae3f5c8b9e68-15d2-40b8-86ac-f808d556f5cd5d064dca-b03b-4fbc-a698-1e906d17e949a0081767-378e-40b4-b825-7993cde90ca5b8284ac5-6b06-4aa7-b01e-822c748bd216dadc72cc-fbbb-4846-9eb0-02449c7e9bb2vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-618e73be1c78cebd98c0451389a4bfe0fed7033b9a99c5dfef4ab081a1711fd0
- Source class
- Nvd cpe vulnerable target
- Assertions
- 6
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
085aa59a-cef9-4c94-9f49-74c8fe8938ff10129ce0-e28e-4ff4-a1c5-a7d7f422559245c51587-7c96-458c-b6d5-e7439deec7ac494bfe79-e8dc-4d64-a90c-ddf3d9548c4a92b6df3f-00bf-4693-9351-f341e3412f41ef91e2d7-d75d-4716-974e-631aca1d0271vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-8754268b8c2cde0fe6aca92689e07534654bf0c32f504fdc7eabdc3dd51c0dab
- Source class
- Nvd cpe vulnerable target
- Assertions
- 6
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
07d26a06-d500-41c6-9262-89f69a4b076940b18dc5-6d88-4fe0-b83d-ad16fa44d50b45895cde-fdeb-4eba-9f73-2d1a98c1c81d5efc1a7d-3425-40d2-8acd-5336790c18b0629da1f8-17f9-4d3f-9a66-622ef5161a18ddc4684a-3c80-4f18-b2d4-84a05dc9de96vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-8f453bafc34e9c461b1290b73550569e7558e64398eede2e74d46d6cb72adae8
- Source class
- Nvd cpe vulnerable target
- Assertions
- 6
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
01355715-8d96-4a0d-97b7-f2f10a02aa2a14d5c640-a70e-4860-a672-a3cf0e80ad90806c9c50-83ac-4c08-aa8f-210175849497c296be47-0fb2-4d7a-bb52-f478580eec34ce8b1289-3980-42f2-af96-7aa2947c8890dc5f87d1-521e-42ba-95d1-312b3112737evendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-b94ca11deae6f3dbdfe71c801d37911c9fd185c5bd3c37c804c67d15918d47d3
- Source class
- Nvd cpe vulnerable target
- Assertions
- 6
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
4bbdcfef-8b07-4173-9e0e-5c519e8069034bd0128d-b0a1-4498-a8fd-59e707ad05ab50c629ab-17fd-4a81-9454-34ea3c4227726576319a-d4ca-4c81-bcf0-f938f0feaf668c51049d-2410-45a0-8820-092d191cc343d99c6e17-b4c3-4bfb-b831-3656f786837dvendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-ba5b29ee89c2340743c5ed2999e757bf44af0086b8b527afdbbe3f8a626803da
- Source class
- Nvd cpe vulnerable target
- Assertions
- 6
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
1a5c8510-cc8f-4500-b07e-756eb303f1e844ebcfd1-0f47-4020-ae29-2f76b0614f12511b5b5b-f07f-40e7-b950-d0b4c29060cb5586120a-21c4-4763-86d8-d91f63b4655b8d45220e-e533-4013-82af-7d349f917e37c9f36587-57f2-414a-a0b4-55f3af3437e6vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-bcf09b1e7f256f8ae475f16dc9eb0c89893ad01b1d9c94b66d17ac875578a078
- Source class
- Nvd cpe vulnerable target
- Assertions
- 6
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
1c326433-d322-4a51-8298-76bff0c06e441f6277af-c732-44d7-99e1-b319c8dc44304c2999f6-7384-425a-b13f-cb3b710011cb7a87a856-9ee4-4fab-a6e7-ebec958578617e5932c3-dbbc-427e-91f1-375abb76d07ee8c35f0d-037f-4267-af83-62b3b5acb538vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-c611bfdeac48cac2141d0aebba0e7ba6ff1c599d72cfe95a76f1db1b7fe68b36
- Source class
- Nvd cpe vulnerable target
- Assertions
- 6
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0acab2e9-1725-4817-8fc0-983a53282bb3383cfc08-8e63-47c3-be90-a3df2667bbc96bca9617-704c-49b6-901c-bf88ca053d8e8958ffd8-7f4d-4b8b-877f-fac44e126a6dd368606b-ef10-43e9-a4ef-dcbdc76ca78cf5590d40-ec6f-4f52-ae39-f455ea88a45avendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-cf4091ca4e2fda20d15e130d8a797ab0e11077ff758509d164c8e77b9177c404
- Source class
- Nvd cpe vulnerable target
- Assertions
- 6
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
04e28f01-4fd3-40e1-ba4a-730705d2ab920c93e6b8-ee8f-4e95-8af7-7d9ae42df0951aa9389c-9b3c-4a6a-87d5-5aa7e67d650398d7464b-05eb-4395-a400-9843d2ac540ab27fe9a2-6089-430c-a9c5-267caf6827c3d7a6b4a3-e8d4-4cfd-ab0b-41de7c4b2b0dvendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-dfc8c075c3b90f711dd6c07c1d70e2c3507742bbcffef3651f2737a4133eeb81
- Source class
- Nvd cpe vulnerable target
- Assertions
- 6
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
1f8d35e6-5532-4ba8-9add-b9f7f629f22c2a1e7c8e-cf1d-4ad9-a73a-917e97cb39607dd3b308-1ed2-460e-950b-e677babf877e8c4a56c6-dcc3-43c4-80ba-85ebeb84bb33be2158f2-199c-46ed-809d-959fe938bcded606d64a-49a0-46d8-90c4-e79ce3a604b8vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-e23ab53fe98a6d7dc5b97fdacee007e8bb696cfe3231c6ccc001c53853c3209c
- Source class
- Nvd cpe vulnerable target
- Assertions
- 6
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
00cf3fa4-f97b-4257-9b92-d62fe18f870b3a6cd4dc-e91f-4996-a1ce-3f41ed50c4297cd65816-2233-43c9-aef7-1bf3d456199bb36017a8-72f9-4387-acc9-2fd57891eb99e7000cad-49bf-43f0-b323-99d6fc720a42f2350b8e-f545-46aa-abbb-42b9116ec18evendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-f87c7b9b64c86afcc0c48220bda1bc92543beefff7155621fe458a2627cfe653
- Source class
- Nvd cpe vulnerable target
- Assertions
- 6
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
7d614a67-2935-4548-99a7-e561b65624d59970416c-86a2-463b-bc60-17e1c88ec914b80708fa-374a-4c23-86ea-73d559e1f86dbbee22ff-c531-4a6c-826f-102bc0a1a142c6c01dc0-1585-4fb8-a068-d4561170be29ef37d840-903e-46d2-b5c6-d049e37d9e1avendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-fe8f45eed4bb3ac6e69f6f6fbf87e9e25862951e870386e176dca756ebfdb2cb
- Source class
- Nvd cpe vulnerable target
- Assertions
- 6
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
4aeb5f5c-b574-4e63-97dd-fd16dd0784a54b65ebea-e695-4fb6-925f-eb23d426dfd97fa963f0-af10-4417-892b-0539ebe8a7d1ca1e668c-9ab5-459a-9253-db1e8784864cca88ac09-8f2a-4c00-9695-13d95d752a4ef6ab2b99-b143-462f-b750-9bf52800125bCanonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
b7244d7a-50a2-4ec9-8c46-95a273b2c014Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAV:N/AC:L/Au:N/C:C/I:C/A:CCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDirect CVE/CNA normalized decisions
CISA-ADP
CVSS 3.1 · Secondary · Independent enrichment · rank 2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Validation
- Valid match
- Recomputed
- 9.8
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.