CISA KEV · catalog date Jan 18, 2022 · first observed Jul 19, 2026
Evidence dossier
CVE-2021-22991
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, undisclosed requests to a virtual…
Exploited in the wild (CISA KEV since Jan 18, 2022). NVD reports CVSS 3.1 9.8. EPSS estimates 61.1% exploit likelihood as of Aug 27, 2026.
As of Aug 27, 2026
Normalized restatement
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, undisclosed requests to a virtual server may be incorrectly handled by the Traffic Management Microkernel (TMM) URI normalization, which may trigger a buffer overflow, resulting in a DoS attack. In certain situations, it may theoretically allow bypass of URL based access control or remote code execution (RCE). Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
- State
- PUBLISHED
- Published
- Mar 31, 2021
- Updated
- Oct 21, 2025
- Evidence coverage
- 99%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAf5Original evidence ↗
Record text: On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, undisclosed requests to a virtual server may be incorrectly handled by the Traffic Management Microkernel (TMM) URI normalization, which may trigger a buffer overflow, resulting in a DoS attack. In certain situations, it may theoretically allow bypass of URL based access control or remote code execution (RCE). Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Inspect raw assertion
- Field
container- Value
- On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, undisclosed requests to a virtual server may be incorrectly handled by the Traffic Management Microkernel (TMM) URI normalization, which may trigger a buffer overflow, resulting in a DoS attack. In certain situations, it may theoretically allow bypass of URL based access control or remote code execution (RCE). Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: F5 BIG-IP Traffic Management Microkernel Buffer Overflow
Inspect raw assertion
- Field
observed_exploitation- Value
- F5 BIG-IP Traffic Management Microkernel Buffer Overflow
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 61.06% probability · 99.09th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.610640000000; percentile 0.990910000000
FIRST EPSS · score date Aug 27, 2026 · 99.1th percentile · first observed Aug 27, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, undisclosed requests to a virtual server may be incorrectly handled by the Traffic Management Microkernel (TMM) URI normalization, which may trigger a buffer overflow, resulting in a DoS attack. In certain situations, it may theoretically allow bypass of URL based access control or remote code execution (RCE). Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Inspect raw assertion
- Field
container- Value
- On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, undisclosed requests to a virtual server may be incorrectly handled by the Traffic Management Microkernel (TMM) URI normalization, which may trigger a buffer overflow, resulting in a DoS attack. In certain situations, it may theoretically allow bypass of URL based access control or remote code execution (RCE). Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
F5 BIG-IP Traffic Management Microkernel Buffer Overflow
Inspect raw assertion
- Field
observed_exploitation- Value
- F5 BIG-IP Traffic Management Microkernel Buffer Overflow
61.06% probability · 99.09th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.610640000000; percentile 0.990910000000
Applicability
Cited product scope
Grouped from 1 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
15 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3"}]product-fe8f45eed4bb3ac6e69f6f6fbf87e9e25862951e870386e176dca756ebfdb2cbLinked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 12.1.0; through excluding 12.1.5.3
- Match ID
14de89cf-f8ee-4e09-9755-81f9a2f44f85
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 2
- Logic
- OR
- Version bounds
- from including 14.1.0; through excluding 14.1.4
- Match ID
fb553a20-d521-4a32-ad49-8ffd5a95e684
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- from including 13.1.0; through excluding 13.1.3.6
- Match ID
8c3a0a32-e425-4939-a30d-95a046abbabb
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 3
- Logic
- OR
- Version bounds
- from including 15.1.0; through excluding 15.1.2.1
- Match ID
6ed8c663-038b-4071-9ff9-ae609f2da4cd
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 4
- Logic
- OR
- Version bounds
- from including 16.0.0; through excluding 16.0.1.1
- Match ID
a7706f70-bf89-480e-9aa6-3fe447375138
product-c611bfdeac48cac2141d0aebba0e7ba6ff1c599d72cfe95a76f1db1b7fe68b36Linked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 7
- Logic
- OR
- Version bounds
- from including 14.1.0; through excluding 14.1.4
- Match ID
dd3fc6d2-5816-47c0-81ae-ded62570f090
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 9
- Logic
- OR
- Version bounds
- from including 16.0.0; through excluding 16.0.1.1
- Match ID
0a84a8d4-9047-46d2-9c26-03c977d47ae4
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 6
- Logic
- OR
- Version bounds
- from including 13.1.0; through excluding 13.1.3.6
- Match ID
fe73e240-2cb5-40cb-8e58-08989f5d0156
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 5
- Logic
- OR
- Version bounds
- from including 12.1.0; through excluding 12.1.5.3
- Match ID
f76ed86b-7c48-4921-af97-68307c181e7d
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 8
- Logic
- OR
- Version bounds
- from including 15.1.0; through excluding 15.1.2.1
- Match ID
f0ac967d-8d6d-44f5-88ef-a50f18979774
product-3159127811fadcfbf55e58810b397c704a5ecb216e89a6fccc26cab6944674c7Linked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 10
- Logic
- OR
- Version bounds
- from including 12.1.0; through excluding 12.1.5.3
- Match ID
12a27d41-6dec-4887-a9a0-fe5aad01fa98
cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 13
- Logic
- OR
- Version bounds
- from including 15.1.0; through excluding 15.1.2.1
- Match ID
61ba4596-efd4-483f-952d-4298b6cefa9d
cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 12
- Logic
- OR
- Version bounds
- from including 14.1.0; through excluding 14.1.4
- Match ID
db183373-a897-43df-a544-364e59358f30
cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 11
- Logic
- OR
- Version bounds
- from including 13.1.0; through excluding 13.1.3.6
- Match ID
39dda652-065c-4af9-a014-e0daff60b61b
cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 14
- Logic
- OR
- Version bounds
- from including 16.0.0; through excluding 16.0.1.1
- Match ID
6b9117da-6aa9-4704-a092-b1d426e6370d
product-000cb533806b78ef860fa6bff163646e9d5756ef6c2d4d7d222692c4cd4c943fLinked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 16
- Logic
- OR
- Version bounds
- from including 13.1.0; through excluding 13.1.3.6
- Match ID
c33ff2cf-2b91-489d-bd48-0cf9b7f0b8a1
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 19
- Logic
- OR
- Version bounds
- from including 16.0.0; through excluding 16.0.1.1
- Match ID
4ae6833c-ff7c-4249-bf98-453645eef8d9
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 15
- Logic
- OR
- Version bounds
- from including 12.1.0; through excluding 12.1.5.3
- Match ID
6b8ab156-1960-4220-8fd2-bf7fbcd91f85
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 18
- Logic
- OR
- Version bounds
- from including 15.1.0; through excluding 15.1.2.1
- Match ID
b462a70a-2504-4e8c-85c3-d771cdb34038
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 17
- Logic
- OR
- Version bounds
- from including 14.1.0; through excluding 14.1.4
- Match ID
f2442894-a473-49a5-95b6-6312c3407fe6
product-bcf09b1e7f256f8ae475f16dc9eb0c89893ad01b1d9c94b66d17ac875578a078Linked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 23
- Logic
- OR
- Version bounds
- from including 15.1.0; through excluding 15.1.2.1
- Match ID
5591e2a0-9d8e-42d2-99e0-62738897762d
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 24
- Logic
- OR
- Version bounds
- from including 16.0.0; through excluding 16.0.1.1
- Match ID
51e3e0a3-8a75-43f8-8e8a-0c07345b88fd
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 22
- Logic
- OR
- Version bounds
- from including 14.1.0; through excluding 14.1.4
- Match ID
78f5dcad-be4e-4d57-82cd-adab32691a9e
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 21
- Logic
- OR
- Version bounds
- from including 13.1.0; through excluding 13.1.3.6
- Match ID
e153e94c-35b3-46df-96b4-0c41ec542954
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 20
- Logic
- OR
- Version bounds
- from including 12.1.0; through excluding 12.1.5.3
- Match ID
8adb41c0-b8dd-4e31-ae7b-959b4de938b1
product-ba5b29ee89c2340743c5ed2999e757bf44af0086b8b527afdbbe3f8a626803daLinked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 26
- Logic
- OR
- Version bounds
- from including 13.1.0; through excluding 13.1.3.6
- Match ID
2bf4f8c6-1c43-4a54-9fd6-011253744fc8
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 25
- Logic
- OR
- Version bounds
- from including 12.1.0; through excluding 12.1.5.3
- Match ID
a921f4e5-6ba7-4978-b47e-d1b173ff493f
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 28
- Logic
- OR
- Version bounds
- from including 15.1.0; through excluding 15.1.2.1
- Match ID
50f6cc82-cac7-426c-94f0-9e8e26cf61e0
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 27
- Logic
- OR
- Version bounds
- from including 14.1.0; through excluding 14.1.4
- Match ID
8b318d4f-0d42-46cd-a5a9-02337bb1d2f2
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 29
- Logic
- OR
- Version bounds
- from including 16.0.0; through excluding 16.0.1.1
- Match ID
7bb77eff-a064-4475-a93c-5d5ba9313724
product-f87c7b9b64c86afcc0c48220bda1bc92543beefff7155621fe458a2627cfe653Linked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 34
- Logic
- OR
- Version bounds
- from including 16.0.0; through excluding 16.0.1.1
- Match ID
40239d12-142e-4d36-a89e-0f7ab91b665a
cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 33
- Logic
- OR
- Version bounds
- from including 15.1.0; through excluding 15.1.2.1
- Match ID
29a3450e-ea73-4e17-b371-92f55ef6e1a9
cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 30
- Logic
- OR
- Version bounds
- from including 12.1.0; through excluding 12.1.5.3
- Match ID
88acf2c5-fd3d-49be-8f32-13559a0c4a63
cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 31
- Logic
- OR
- Version bounds
- from including 13.1.0; through excluding 13.1.3.6
- Match ID
090fc11a-c085-4603-84e0-3abd6c571e2b
cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 32
- Logic
- OR
- Version bounds
- from including 14.1.0; through excluding 14.1.4
- Match ID
ae2899e6-abef-4b61-ab8d-af060d571196
product-8f453bafc34e9c461b1290b73550569e7558e64398eede2e74d46d6cb72adae8Linked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 35
- Logic
- OR
- Version bounds
- from including 12.1.0; through excluding 12.1.5.3
- Match ID
7689c97e-d5fb-427f-9fba-a41ca0ec7f06
cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 36
- Logic
- OR
- Version bounds
- from including 13.1.0; through excluding 13.1.3.6
- Match ID
29a0b309-e321-4f87-9c36-cae4c213c14b
cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 39
- Logic
- OR
- Version bounds
- from including 16.0.0; through excluding 16.0.1.1
- Match ID
87ca1319-92d4-4c2f-b5d4-a2e86f538007
cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 38
- Logic
- OR
- Version bounds
- from including 15.1.0; through excluding 15.1.2.1
- Match ID
d4d4b28e-43b5-4132-a4ec-b20b9f85964a
cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 37
- Logic
- OR
- Version bounds
- from including 14.1.0; through excluding 14.1.4
- Match ID
f7c6025c-7283-4568-929b-cfa11423e179
product-e23ab53fe98a6d7dc5b97fdacee007e8bb696cfe3231c6ccc001c53853c3209cLinked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 44
- Logic
- OR
- Version bounds
- from including 16.0.0; through excluding 16.0.1.1
- Match ID
7fe9ef68-055b-40b2-a676-c4c7faaf77b3
cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 43
- Logic
- OR
- Version bounds
- from including 15.1.0; through excluding 15.1.2.1
- Match ID
626e1218-868c-4328-99da-62785c6771df
cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 41
- Logic
- OR
- Version bounds
- from including 13.1.0; through excluding 13.1.3.6
- Match ID
da2d429f-42c4-4872-977a-cdabd60f92e6
cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 40
- Logic
- OR
- Version bounds
- from including 12.1.0; through excluding 12.1.5.3
- Match ID
9dc500f0-4d91-415e-b754-a89f730002f9
cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 42
- Logic
- OR
- Version bounds
- from including 14.1.0; through excluding 14.1.4
- Match ID
bbbad42c-06d5-437f-ab92-1dcc23c1a78b
product-618e73be1c78cebd98c0451389a4bfe0fed7033b9a99c5dfef4ab081a1711fd0Linked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 47
- Logic
- OR
- Version bounds
- from including 14.1.0; through excluding 14.1.4
- Match ID
3db5f9d2-c452-4469-9626-15fa11960a9c
cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 49
- Logic
- OR
- Version bounds
- from including 16.0.0; through excluding 16.0.1.1
- Match ID
bd28da4b-f671-41b8-b231-24d28682fe8f
cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 45
- Logic
- OR
- Version bounds
- from including 12.1.0; through excluding 12.1.5.3
- Match ID
b58942bf-915d-49f6-9e8a-2092d1ae572d
cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 46
- Logic
- OR
- Version bounds
- from including 13.1.0; through excluding 13.1.3.6
- Match ID
59be59f9-e6f3-4d48-89ac-6c4b5635a4e9
cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 48
- Logic
- OR
- Version bounds
- from including 15.1.0; through excluding 15.1.2.1
- Match ID
044f30a3-6b2e-4c38-8705-d291cd3cb287
product-8754268b8c2cde0fe6aca92689e07534654bf0c32f504fdc7eabdc3dd51c0dabLinked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 53
- Logic
- OR
- Version bounds
- from including 15.1.0; through excluding 15.1.2.1
- Match ID
1d513aca-0d21-4ce0-88c1-dca812f62c05
cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 50
- Logic
- OR
- Version bounds
- from including 12.1.0; through excluding 12.1.5.3
- Match ID
4fd31b8d-10ae-4e52-8235-6eb4a12d3965
cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 54
- Logic
- OR
- Version bounds
- from including 16.0.0; through excluding 16.0.1.1
- Match ID
47980a60-f9b6-47ee-ad74-4d6d03a71ad0
cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 51
- Logic
- OR
- Version bounds
- from including 13.1.0; through excluding 13.1.3.6
- Match ID
0a9aa005-d0e3-43fc-9d21-9db8b5b9495d
cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 52
- Logic
- OR
- Version bounds
- from including 14.1.0; through excluding 14.1.4
- Match ID
57388787-f9df-4930-acbc-f3d1daa53190
product-dfc8c075c3b90f711dd6c07c1d70e2c3507742bbcffef3651f2737a4133eeb81Linked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 57
- Logic
- OR
- Version bounds
- from including 14.1.0; through excluding 14.1.4
- Match ID
0af0d639-0210-47d0-8680-6e09f0111d5d
cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 58
- Logic
- OR
- Version bounds
- from including 15.1.0; through excluding 15.1.2.1
- Match ID
86607f4a-555f-4842-afa8-34eb7484fa2e
cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 59
- Logic
- OR
- Version bounds
- from including 16.0.0; through excluding 16.0.1.1
- Match ID
b0901863-b55a-4c97-b9ac-b537d242d2bf
cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 56
- Logic
- OR
- Version bounds
- from including 13.1.0; through excluding 13.1.3.6
- Match ID
94906b0a-46d2-41fc-bcfd-c66910274cd5
cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 55
- Logic
- OR
- Version bounds
- from including 12.1.0; through excluding 12.1.5.3
- Match ID
58a15dc4-30f5-407c-bce4-bc877c73480a
product-b94ca11deae6f3dbdfe71c801d37911c9fd185c5bd3c37c804c67d15918d47d3Linked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 61
- Logic
- OR
- Version bounds
- from including 13.1.0; through excluding 13.1.3.6
- Match ID
45d3b1bc-568e-4bd8-8774-75203751c754
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 62
- Logic
- OR
- Version bounds
- from including 14.1.0; through excluding 14.1.4
- Match ID
704df342-2cb5-4791-bf30-294d07b53653
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 60
- Logic
- OR
- Version bounds
- from including 12.1.0; through excluding 12.1.5.3
- Match ID
d14a8876-b566-4a0c-886d-daec77bb3689
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 63
- Logic
- OR
- Version bounds
- from including 15.1.0; through excluding 15.1.2.1
- Match ID
43cb3fea-4127-460b-846e-81b6c985deaa
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 64
- Logic
- OR
- Version bounds
- from including 16.0.0; through excluding 16.0.1.1
- Match ID
85065c6e-71f2-42b8-a169-51174987b8af
product-cf4091ca4e2fda20d15e130d8a797ab0e11077ff758509d164c8e77b9177c404Linked exactInspect raw assertions
cpe:2.3:a:f5:ssl_orchestrator:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 67
- Logic
- OR
- Version bounds
- from including 14.1.0; through excluding 14.1.4
- Match ID
c3fe49a0-46b4-49a1-92a4-1bea5bf48cdf
cpe:2.3:a:f5:ssl_orchestrator:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 66
- Logic
- OR
- Version bounds
- from including 13.1.0; through excluding 13.1.3.6
- Match ID
6c5de2da-0daf-4ddf-9acb-daf301b97fb9
cpe:2.3:a:f5:ssl_orchestrator:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 68
- Logic
- OR
- Version bounds
- from including 15.1.0; through excluding 15.1.2.1
- Match ID
628a35c2-d3d8-40a2-ba55-0910a38036e4
cpe:2.3:a:f5:ssl_orchestrator:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 69
- Logic
- OR
- Version bounds
- from including 16.0.0; through excluding 16.0.1.1
- Match ID
14edd6bb-094c-409f-b702-ec87867eba17
cpe:2.3:a:f5:ssl_orchestrator:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 65
- Logic
- OR
- Version bounds
- from including 12.1.0; through excluding 12.1.5.3
- Match ID
34683a56-1665-47c7-a150-246b8a86c363
Affected-product evidence
Accepted scope and product mapping
14 canonical links · 1 source-reported links
vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-000cb533806b78ef860fa6bff163646e9d5756ef6c2d4d7d222692c4cd4c943f
- Source class
- Nvd cpe vulnerable target
- Assertions
- 5
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
97bea03c-fa0e-42a8-868a-0bae4bb4b399ae77db5d-89a9-4a99-83c8-6f9e13167803bf13e9f1-9c5e-4d98-aefa-d04470b2d44ddb5e2865-c583-44a6-8da6-f124030fd57ff48a73be-1081-4b86-90c2-e29d8473eeacvendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-3159127811fadcfbf55e58810b397c704a5ecb216e89a6fccc26cab6944674c7
- Source class
- Nvd cpe vulnerable target
- Assertions
- 5
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
03cbc2a9-24bb-419a-8090-e019bc0d360a3b4153f8-3e83-4398-a9e7-42b809af0a2556173662-f46e-417e-9d79-0fd84e5e5d02851d7511-4bf2-45da-855d-d7450b2b4c2aa2932c8c-6c78-4e94-b979-7ab68a8c09cdvendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-618e73be1c78cebd98c0451389a4bfe0fed7033b9a99c5dfef4ab081a1711fd0
- Source class
- Nvd cpe vulnerable target
- Assertions
- 5
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
22201b83-99ae-49e1-8c93-a4d812b9977156dfdca1-2f39-42c0-9b87-16f64280400979f54f14-1692-4d22-89fd-74cd3eb863618f2678cd-f5f1-4e09-8b0d-3fa8ecd9ff53c84dfe93-f7bc-4489-bbf9-be03b7781035vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-8754268b8c2cde0fe6aca92689e07534654bf0c32f504fdc7eabdc3dd51c0dab
- Source class
- Nvd cpe vulnerable target
- Assertions
- 5
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0bf9176e-e87e-43ad-865d-2275ef67df65607c9cea-ae27-4086-a04e-fbf6b9fc46da9868e03e-cebe-41ba-ace7-a676763e537e9a2135c1-df9a-45c4-a4f4-54af2e22dd6ddac6e114-fb93-42b7-9e5c-65b3262fe8f0vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-8f453bafc34e9c461b1290b73550569e7558e64398eede2e74d46d6cb72adae8
- Source class
- Nvd cpe vulnerable target
- Assertions
- 5
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0a77adb4-07d9-438f-93ff-e5f59ce3ec5c1d187f46-2dfc-42d8-af57-67ade5c98d2550267ee2-8470-4c1d-9a97-728ca77efeb4906dd027-6fcb-4457-8c52-4e7dbd93aaaea6fe52b2-1225-49de-af8b-4532b80a4058vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-b94ca11deae6f3dbdfe71c801d37911c9fd185c5bd3c37c804c67d15918d47d3
- Source class
- Nvd cpe vulnerable target
- Assertions
- 5
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
1c81e45d-c73f-43fb-8491-ef3d8a73778487454ecf-249d-4363-855d-ef103fef4c6c8f0a2ac1-e218-4003-8b62-4608dcc33a7bee130935-b397-42ef-bf8d-ece6525dbf5cf9e1de8e-b163-4c50-a068-43772898d37bvendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-ba5b29ee89c2340743c5ed2999e757bf44af0086b8b527afdbbe3f8a626803da
- Source class
- Nvd cpe vulnerable target
- Assertions
- 5
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
31173f9c-0f0e-4980-8ba2-3c41d8fe955a69353009-6a91-4eb0-ad4a-d7d3854fd2326fcb8fcb-1d50-448b-bf64-b66e028729e08189181b-aabf-4c42-a032-686c94436397e425cec6-63e4-4ae0-bf95-dc1bb4ea6d58vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-bcf09b1e7f256f8ae475f16dc9eb0c89893ad01b1d9c94b66d17ac875578a078
- Source class
- Nvd cpe vulnerable target
- Assertions
- 5
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0ae7fdd0-02c5-4a6c-9464-a56f544ae6f715108ba6-72e0-40cf-a1e9-9eaaf6bfb97d9215c6ec-d265-4f78-a48e-adb913c13826b321b682-9772-437b-8fb3-08c9bcd3ed98e5c71dfe-6973-43c7-bbbe-5174a65467d1vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-c611bfdeac48cac2141d0aebba0e7ba6ff1c599d72cfe95a76f1db1b7fe68b36
- Source class
- Nvd cpe vulnerable target
- Assertions
- 5
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0bd63bad-ac34-4568-b252-bb409856f8154fc6a8a6-f5ad-43f5-9853-dd864149a4d7e96a5011-5c64-4084-a206-16f7cc3c69f9f4416f89-c0cf-4921-a46b-bf765ddf18e2f51cd12e-4976-4f2a-9c19-bb53beedabe7vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-cf4091ca4e2fda20d15e130d8a797ab0e11077ff758509d164c8e77b9177c404
- Source class
- Nvd cpe vulnerable target
- Assertions
- 5
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
096a4979-dfa7-4515-87f1-0f12ae5ee3b8389a39b8-8749-4c30-b121-28a71df0858962695fc4-f35e-4cd2-9cc3-611dee74083c8b0b7511-b158-4452-966f-6fd1cc98d905e11bf497-fcee-45d1-ae0e-0467926507b5vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-dfc8c075c3b90f711dd6c07c1d70e2c3507742bbcffef3651f2737a4133eeb81
- Source class
- Nvd cpe vulnerable target
- Assertions
- 5
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
2a97f7b1-6a5e-469a-bc9e-7dff203eee808424005c-05c5-481e-89f9-8ad4b2b51e4a8fcc4115-c17d-4785-bc43-a188834395aa973a7843-60c8-4f9a-ac88-3c9a2666c235a145e6c2-9a93-41bf-bd99-fa4497d9f946vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-e23ab53fe98a6d7dc5b97fdacee007e8bb696cfe3231c6ccc001c53853c3209c
- Source class
- Nvd cpe vulnerable target
- Assertions
- 5
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
26d977f6-59e2-45e5-8883-6676593f49d96120a9a8-2aa4-4566-9ec1-efede274e1a278c9c240-e5a7-4375-b918-d448983d106e852b4d39-4d84-41c7-aa39-42b396c0b1bba8d8ae4a-14ce-46a5-a53c-f370c52b3a5cvendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-f87c7b9b64c86afcc0c48220bda1bc92543beefff7155621fe458a2627cfe653
- Source class
- Nvd cpe vulnerable target
- Assertions
- 5
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
1b3c6f3d-6bd3-48a7-9f98-d8aa813702561ff37464-25de-461b-9f03-8c256671c9cdb0ba294b-2975-44fa-b3bd-841c958951a3b72f0efe-0741-4434-a6d2-3e44de8e8b58fb3c65de-5c58-4bdc-85b7-fee06f4e07c8vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-fe8f45eed4bb3ac6e69f6f6fbf87e9e25862951e870386e176dca756ebfdb2cb
- Source class
- Nvd cpe vulnerable target
- Assertions
- 5
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
29152711-f9f3-4a10-9c78-eb5c0ad4484137250218-b7f5-4fd0-9e49-36f9f392a5f673af8827-6bdb-42c3-af5c-2669be44e2668a1148b5-311a-41e2-921b-b1dda2ea33d39562b2ba-21c3-45ae-ba8c-f5d2a56cd30fCanonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
dc9c1648-79e6-46f6-991d-2387408bc997Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAV:N/AC:M/Au:N/C:P/I:P/A:PCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDirect CVE/CNA normalized decisions
CISA-ADP
CVSS 3.1 · Secondary · Independent enrichment · rank 2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Validation
- Valid match
- Recomputed
- 9.8
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.