Evidence dossier

CVE-2022-1388

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x…

Exploited in the wild (CISA KEV since May 10, 2022). f5 reports CVSS 3.1 9.8. EPSS estimates 100.0% exploit likelihood as of Aug 2, 2026.

91.091.9Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

State
PUBLISHED
Published
May 5, 2022
Updated
Oct 21, 2025
Evidence coverage
99%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    f5

    Record text: On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

    Inspect raw assertion
    Field
    container
    Value
    On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: F5 BIG-IP Missing Authentication Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    F5 BIG-IP Missing Authentication Vulnerability
    Original evidence ↗
  5. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 99.96% probability · 99.98th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.999580000000; percentile 0.999750000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date May 10, 2022 · first observed Jul 19, 2026

Exploit likelihood99.96%

FIRST EPSS · score date Aug 2, 2026 · 100th percentile · first observed Aug 2, 2026

SeverityCVSS 9.8

f5 · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

casca-unknown-reasons-v1
Exploitation statusEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Exploit likelihoodEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Severity assessmentEvidence supported

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Aug 27, 2026
Resolution
None
Affected productsSource-reported scope

The cited source assertion is retained while canonical product linkage remains open.

Revision
casca-factor-d-obligations-v1
Cutoff
Aug 27, 2026
Resolution
Resolve identity

Source comparison

Who said what

CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
f5Original assertion
Record text

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

Inspect raw assertion
Field
container
Value
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

F5 BIG-IP Missing Authentication Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
F5 BIG-IP Missing Authentication Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

99.96% probability · 99.98th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.999580000000; percentile 0.999750000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
66Underlying assertions
11Canonical products
66Target assertions
0Constraint assertions

Grouped from 1 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

12 scope groups

f5 · source assertedF5BIG-IPDirect source scope
Unaffected: 17.0.0 to before 17.0.x* (custom comparison)Affected: 16.1.x to before 16.1.2.2 (custom comparison)Affected: 15.1.x to before 15.1.5.1 (custom comparison)Affected: 14.1.x to before 14.1.4.6 (custom comparison)Affected: 13.1.x to before 13.1.5 (custom comparison)Affected: 12.1.x through 12.1.6 (custom comparison)Affected: 11.6.x through 11.6.5 (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "unaffected", "version": "17.0.0", "lessThan": "17.0.x*", "versionType": "custom"}, {"status": "affected", "version": "16.1.x", "lessThan": "16.1.2.2", "versionType": "custom"}, {"status": "affected", "version": "15.1.x", "lessThan": "15.1.5.1", "versionType": "custom"}, {"status": "affected", "version": "14.1.x", "lessThan": "14.1.4.6", "versionType": "custom"}, {"status": "affected", "version": "13.1.x", "lessThan": "13.1.5", "versionType": "custom"}, {"status": "affected", "version": "12.1.x", "versionType": "custom", "lessThanOrEqual": "12.1.6"}, {"status": "affected", "version": "11.6.x", "versionType": "custom", "lessThanOrEqual": "11.6.5"}]
NVD CPE · APPLICATIONf5big-ip_access_policy_managerVulnerable target · 6 assertions
Any version (unconstrained) (>= 11.6.1, <= 11.6.5); Any version (unconstrained) (>= 12.1.0, <= 12.1.6); Any version (unconstrained) (>= 13.1.0, < 13.1.5); Any version (unconstrained) (>= 14.1.0, < 14.1.4.6); Any version (unconstrained) (>= 15.1.0, < 15.1.5.1); Any version (unconstrained) (>= 16.1.0, < 16.1.2.2)Canonical identity product-fe8f45eed4bb3ac6e69f6f6fbf87e9e25862951e870386e176dca756ebfdb2cbLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 12.1.0; through including 12.1.6
    Match ID
    de2f2cb2-be96-4dc8-b336-1e9a318b4604
  2. cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 5
    Logic
    OR
    Version bounds
    from including 16.1.0; through excluding 16.1.2.2
    Match ID
    758d4f60-c707-4c09-8fa1-9afc232c2b68
  3. cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 11.6.1; through including 11.6.5
    Match ID
    2fba9552-4645-4bff-91a4-47b6a3414325
  4. cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 13.1.0; through excluding 13.1.5
    Match ID
    b31ba594-f521-4ae6-b1b6-6f1f5ab735f5
  5. cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 14.1.0; through excluding 14.1.4.6
    Match ID
    d2e2c67c-cf1b-4d54-a65d-1ad14da61199
  6. cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 15.1.0; through excluding 15.1.5.1
    Match ID
    f699242d-ca23-47d7-bb53-c96a7ef82239
NVD CPE · APPLICATIONf5big-ip_advanced_firewall_managerVulnerable target · 6 assertions
Any version (unconstrained) (>= 11.6.1, <= 11.6.5); Any version (unconstrained) (>= 12.1.0, <= 12.1.6); Any version (unconstrained) (>= 13.1.0, < 13.1.5); Any version (unconstrained) (>= 14.1.0, < 14.1.4.6); Any version (unconstrained) (>= 15.1.0, < 15.1.5.1); Any version (unconstrained) (>= 16.1.0, < 16.1.2.2)Canonical identity product-c611bfdeac48cac2141d0aebba0e7ba6ff1c599d72cfe95a76f1db1b7fe68b36Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 9
    Logic
    OR
    Version bounds
    from including 14.1.0; through excluding 14.1.4.6
    Match ID
    5b12b864-cf0e-4015-b898-9ff24956898d
  2. cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 11
    Logic
    OR
    Version bounds
    from including 16.1.0; through excluding 16.1.2.2
    Match ID
    4b89c592-e704-4aa8-98ef-22e81a888d9f
  3. cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 6
    Logic
    OR
    Version bounds
    from including 11.6.1; through including 11.6.5
    Match ID
    61d1b91f-8672-4947-af9a-f635679d0fb7
  4. cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 7
    Logic
    OR
    Version bounds
    from including 12.1.0; through including 12.1.6
    Match ID
    6e32cbe0-bfdc-4dcb-a365-2f3c4d680446
  5. cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 8
    Logic
    OR
    Version bounds
    from including 13.1.0; through excluding 13.1.5
    Match ID
    fb153379-872c-4800-af9e-4219559291fd
  6. cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 10
    Logic
    OR
    Version bounds
    from including 15.1.0; through excluding 15.1.5.1
    Match ID
    e336c11e-2544-4ad1-a16b-640db335048f
NVD CPE · APPLICATIONf5big-ip_analyticsVulnerable target · 6 assertions
Any version (unconstrained) (>= 11.6.1, <= 11.6.5); Any version (unconstrained) (>= 12.1.0, <= 12.1.6); Any version (unconstrained) (>= 13.1.0, < 13.1.5); Any version (unconstrained) (>= 14.1.0, < 14.1.4.6); Any version (unconstrained) (>= 15.1.0, < 15.1.5.1); Any version (unconstrained) (>= 16.1.0, < 16.1.2.2)Canonical identity product-000cb533806b78ef860fa6bff163646e9d5756ef6c2d4d7d222692c4cd4c943fLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 17
    Logic
    OR
    Version bounds
    from including 16.1.0; through excluding 16.1.2.2
    Match ID
    6025496d-61a0-444d-85ff-9eb452fdc12d
  2. cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 12
    Logic
    OR
    Version bounds
    from including 11.6.1; through including 11.6.5
    Match ID
    c3787453-ece9-4958-8fd8-8a43a9f86077
  3. cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 13
    Logic
    OR
    Version bounds
    from including 12.1.0; through including 12.1.6
    Match ID
    18666b67-a6ea-402b-926e-96348ab82831
  4. cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 16
    Logic
    OR
    Version bounds
    from including 15.1.0; through excluding 15.1.5.1
    Match ID
    0e079b86-18a3-48d4-9413-d4ebb35e2682
  5. cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 14
    Logic
    OR
    Version bounds
    from including 13.1.0; through excluding 13.1.5
    Match ID
    c3b5c349-cf76-4c87-9a4f-86769f5666cd
  6. cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 15
    Logic
    OR
    Version bounds
    from including 14.1.0; through excluding 14.1.4.6
    Match ID
    4e7a0b6b-f4b2-4e02-b49e-4cced696971f
NVD CPE · APPLICATIONf5big-ip_application_acceleration_managerVulnerable target · 6 assertions
Any version (unconstrained) (>= 11.6.1, <= 11.6.5); Any version (unconstrained) (>= 12.1.0, <= 12.1.6); Any version (unconstrained) (>= 13.1.0, < 13.1.5); Any version (unconstrained) (>= 14.1.0, < 14.1.4.6); Any version (unconstrained) (>= 15.1.0, < 15.1.5.1); Any version (unconstrained) (>= 16.1.0, < 16.1.2.2)Canonical identity product-bcf09b1e7f256f8ae475f16dc9eb0c89893ad01b1d9c94b66d17ac875578a078Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 18
    Logic
    OR
    Version bounds
    from including 11.6.1; through including 11.6.5
    Match ID
    05ed802a-a8a0-4e96-ab45-811a98aa11c2
  2. cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 23
    Logic
    OR
    Version bounds
    from including 16.1.0; through excluding 16.1.2.2
    Match ID
    9965a0fa-84ce-4e7c-92c8-c74a44f401e2
  3. cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 21
    Logic
    OR
    Version bounds
    from including 14.1.0; through excluding 14.1.4.6
    Match ID
    de3ac626-dc9b-4da1-aba0-335b3e20eae8
  4. cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 22
    Logic
    OR
    Version bounds
    from including 15.1.0; through excluding 15.1.5.1
    Match ID
    e827a475-5a25-4485-8f51-4a39cdb89201
  5. cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 19
    Logic
    OR
    Version bounds
    from including 12.1.0; through including 12.1.6
    Match ID
    8af5b8c5-98f2-45b5-a877-c3666e3d6876
  6. cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 20
    Logic
    OR
    Version bounds
    from including 13.1.0; through excluding 13.1.5
    Match ID
    2b937d3c-6d0e-4d87-b9b0-a58a2866a37f
NVD CPE · APPLICATIONf5big-ip_application_security_managerVulnerable target · 6 assertions
Any version (unconstrained) (>= 11.6.1, <= 11.6.5); Any version (unconstrained) (>= 12.1.0, <= 12.1.6); Any version (unconstrained) (>= 13.1.0, < 13.1.5); Any version (unconstrained) (>= 14.1.0, < 14.1.4.6); Any version (unconstrained) (>= 15.1.0, < 15.1.5.1); Any version (unconstrained) (>= 16.1.0, < 16.1.2.2)Canonical identity product-ba5b29ee89c2340743c5ed2999e757bf44af0086b8b527afdbbe3f8a626803daLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 26
    Logic
    OR
    Version bounds
    from including 13.1.0; through excluding 13.1.5
    Match ID
    93768065-555d-46ea-a6e4-00ea467573aa
  2. cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 24
    Logic
    OR
    Version bounds
    from including 11.6.1; through including 11.6.5
    Match ID
    b15992e6-85b6-4e62-a284-fe4b78f5f373
  3. cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 27
    Logic
    OR
    Version bounds
    from including 14.1.0; through excluding 14.1.4.6
    Match ID
    cddfdbfd-8183-4f38-a1e9-b26a087f5edf
  4. cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 29
    Logic
    OR
    Version bounds
    from including 16.1.0; through excluding 16.1.2.2
    Match ID
    0bda0faf-471b-415f-820c-446edd53e327
  5. cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 28
    Logic
    OR
    Version bounds
    from including 15.1.0; through excluding 15.1.5.1
    Match ID
    8a6ec6b2-9cde-467b-94ed-4cd1214435a6
  6. cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 25
    Logic
    OR
    Version bounds
    from including 12.1.0; through including 12.1.6
    Match ID
    1849279e-9fb1-4d6a-8386-337f7df151df
NVD CPE · APPLICATIONf5big-ip_domain_name_systemVulnerable target · 6 assertions
Any version (unconstrained) (>= 11.6.1, <= 11.6.5); Any version (unconstrained) (>= 12.1.0, <= 12.1.6); Any version (unconstrained) (>= 13.1.0, < 13.1.5); Any version (unconstrained) (>= 14.1.0, < 14.1.4.6); Any version (unconstrained) (>= 15.1.0, < 15.1.5.1); Any version (unconstrained) (>= 16.1.0, < 16.1.2.2)Canonical identity product-8f453bafc34e9c461b1290b73550569e7558e64398eede2e74d46d6cb72adae8Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 32
    Logic
    OR
    Version bounds
    from including 13.1.0; through excluding 13.1.5
    Match ID
    fb5b9015-1d83-46f8-a328-286d5cf811dc
  2. cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 31
    Logic
    OR
    Version bounds
    from including 12.1.0; through including 12.1.6
    Match ID
    f489e5b1-1ec4-4e45-8ee6-6a4fcd0f386f
  3. cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 33
    Logic
    OR
    Version bounds
    from including 14.1.0; through excluding 14.1.4.6
    Match ID
    18b014ec-59dc-4956-a7f9-fdcce6802701
  4. cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 34
    Logic
    OR
    Version bounds
    from including 15.1.0; through excluding 15.1.5.1
    Match ID
    9bcba7d9-05c4-4804-9dd9-6400d7717b71
  5. cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 30
    Logic
    OR
    Version bounds
    from including 11.6.1; through including 11.6.5
    Match ID
    8376922b-0d04-4e5d-bade-0d6ac23a4696
  6. cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 35
    Logic
    OR
    Version bounds
    from including 16.1.0; through excluding 16.1.2.2
    Match ID
    f4e0a3c3-f168-47d6-a54d-09722be9ec92
NVD CPE · APPLICATIONf5big-ip_fraud_protection_serviceVulnerable target · 6 assertions
Any version (unconstrained) (>= 11.6.1, <= 11.6.5); Any version (unconstrained) (>= 12.1.0, <= 12.1.6); Any version (unconstrained) (>= 13.1.0, < 13.1.5); Any version (unconstrained) (>= 14.1.0, < 14.1.4.6); Any version (unconstrained) (>= 15.1.0, < 15.1.5.1); Any version (unconstrained) (>= 16.1.0, < 16.1.2.2)Canonical identity product-e23ab53fe98a6d7dc5b97fdacee007e8bb696cfe3231c6ccc001c53853c3209cLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 37
    Logic
    OR
    Version bounds
    from including 12.1.0; through including 12.1.6
    Match ID
    01c01794-36bd-4783-b962-07000fce4788
  2. cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 40
    Logic
    OR
    Version bounds
    from including 15.1.0; through excluding 15.1.5.1
    Match ID
    97923ba5-db8d-46cb-89de-a2ab313557da
  3. cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 39
    Logic
    OR
    Version bounds
    from including 14.1.0; through excluding 14.1.4.6
    Match ID
    3c1c42ef-0217-4a0f-b327-f9419745dc0d
  4. cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 38
    Logic
    OR
    Version bounds
    from including 13.1.0; through excluding 13.1.5
    Match ID
    cf82d6c0-df3b-4f0e-b4a1-fdc7e3c9fecc
  5. cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 36
    Logic
    OR
    Version bounds
    from including 11.6.1; through including 11.6.5
    Match ID
    0471086d-b70e-4b87-862e-01fb99b0d5d5
  6. cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 41
    Logic
    OR
    Version bounds
    from including 16.1.0; through excluding 16.1.2.2
    Match ID
    800b3d3b-45ff-406f-8a32-70e00d2f9de5
NVD CPE · APPLICATIONf5big-ip_global_traffic_managerVulnerable target · 6 assertions
Any version (unconstrained) (>= 11.6.1, <= 11.6.5); Any version (unconstrained) (>= 12.1.0, <= 12.1.6); Any version (unconstrained) (>= 13.1.0, < 13.1.5); Any version (unconstrained) (>= 14.1.0, < 14.1.4.6); Any version (unconstrained) (>= 15.1.0, < 15.1.5.1); Any version (unconstrained) (>= 16.1.0, < 16.1.2.2)Canonical identity product-618e73be1c78cebd98c0451389a4bfe0fed7033b9a99c5dfef4ab081a1711fd0Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 46
    Logic
    OR
    Version bounds
    from including 15.1.0; through excluding 15.1.5.1
    Match ID
    e0dd60ec-40a6-48da-b2b9-b1881820056e
  2. cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 42
    Logic
    OR
    Version bounds
    from including 11.6.1; through including 11.6.5
    Match ID
    cd3d5803-35a0-4ff7-9ad3-e345c53a18fc
  3. cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 44
    Logic
    OR
    Version bounds
    from including 13.1.0; through excluding 13.1.5
    Match ID
    c7748e16-f5e4-4d23-a9bf-b9a5b6462536
  4. cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 43
    Logic
    OR
    Version bounds
    from including 12.1.0; through including 12.1.6
    Match ID
    5ed5a4f4-9fff-43d0-b17d-838d6ceddf04
  5. cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 45
    Logic
    OR
    Version bounds
    from including 14.1.0; through excluding 14.1.4.6
    Match ID
    025f4f45-7eb2-4c8f-9f85-aef4844a943d
  6. cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 47
    Logic
    OR
    Version bounds
    from including 16.1.0; through excluding 16.1.2.2
    Match ID
    3816aee7-81a4-46f4-97ec-b156da52c04d
NVD CPE · APPLICATIONf5big-ip_link_controllerVulnerable target · 6 assertions
Any version (unconstrained) (>= 11.6.1, <= 11.6.5); Any version (unconstrained) (>= 12.1.0, <= 12.1.6); Any version (unconstrained) (>= 13.1.0, < 13.1.5); Any version (unconstrained) (>= 14.1.0, < 14.1.4.6); Any version (unconstrained) (>= 15.1.0, < 15.1.5.1); Any version (unconstrained) (>= 16.1.0, < 16.1.2.2)Canonical identity product-8754268b8c2cde0fe6aca92689e07534654bf0c32f504fdc7eabdc3dd51c0dabLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 48
    Logic
    OR
    Version bounds
    from including 11.6.1; through including 11.6.5
    Match ID
    e20dfbd1-5469-4330-81b1-078d6487c01d
  2. cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 50
    Logic
    OR
    Version bounds
    from including 13.1.0; through excluding 13.1.5
    Match ID
    faf9d095-ac38-415a-b97e-909563da7c89
  3. cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 53
    Logic
    OR
    Version bounds
    from including 16.1.0; through excluding 16.1.2.2
    Match ID
    384fd000-3901-4b01-b544-de210fcfb3b1
  4. cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 52
    Logic
    OR
    Version bounds
    from including 15.1.0; through excluding 15.1.5.1
    Match ID
    f702c966-4d1b-419a-8853-975de634fe2c
  5. cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 51
    Logic
    OR
    Version bounds
    from including 14.1.0; through excluding 14.1.4.6
    Match ID
    f94750c3-d5b8-4397-8211-5eeef947bceb
  6. cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 49
    Logic
    OR
    Version bounds
    from including 12.1.0; through including 12.1.6
    Match ID
    16234a51-9c86-484a-b8d5-6efb838cb564
NVD CPE · APPLICATIONf5big-ip_local_traffic_managerVulnerable target · 6 assertions
Any version (unconstrained) (>= 11.6.1, <= 11.6.5); Any version (unconstrained) (>= 12.1.0, <= 12.1.6); Any version (unconstrained) (>= 13.1.0, < 13.1.5); Any version (unconstrained) (>= 14.1.0, < 14.1.4.6); Any version (unconstrained) (>= 15.1.0, < 15.1.5.1); Any version (unconstrained) (>= 16.1.0, < 16.1.2.2)Canonical identity product-dfc8c075c3b90f711dd6c07c1d70e2c3507742bbcffef3651f2737a4133eeb81Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 57
    Logic
    OR
    Version bounds
    from including 14.1.0; through excluding 14.1.4.6
    Match ID
    b9242bca-366b-4c8b-a9e9-fa422addf18d
  2. cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 55
    Logic
    OR
    Version bounds
    from including 12.1.0; through including 12.1.6
    Match ID
    61189d3b-8bf1-47a7-b5ac-a75e44d6bd5f
  3. cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 56
    Logic
    OR
    Version bounds
    from including 13.1.0; through excluding 13.1.5
    Match ID
    260092b3-ca15-4ece-b4f9-075c714ffe76
  4. cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 59
    Logic
    OR
    Version bounds
    from including 16.1.0; through excluding 16.1.2.2
    Match ID
    652e0726-38db-4559-bac1-860e02678f60
  5. cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 54
    Logic
    OR
    Version bounds
    from including 11.6.1; through including 11.6.5
    Match ID
    f92f2449-8a6e-431e-8cb1-5255d2464b31
  6. cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 58
    Logic
    OR
    Version bounds
    from including 15.1.0; through excluding 15.1.5.1
    Match ID
    0ff9bcd4-9631-4ac9-95b2-da7688fda703
NVD CPE · APPLICATIONf5big-ip_policy_enforcement_managerVulnerable target · 6 assertions
Any version (unconstrained) (>= 11.6.1, <= 11.6.5); Any version (unconstrained) (>= 12.1.0, <= 12.1.6); Any version (unconstrained) (>= 13.1.0, < 13.1.5); Any version (unconstrained) (>= 14.1.0, < 14.1.4.6); Any version (unconstrained) (>= 15.1.0, < 15.1.5.1); Any version (unconstrained) (>= 16.1.0, < 16.1.2.2)Canonical identity product-b94ca11deae6f3dbdfe71c801d37911c9fd185c5bd3c37c804c67d15918d47d3Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 60
    Logic
    OR
    Version bounds
    from including 11.6.1; through including 11.6.5
    Match ID
    53f940f3-6cf4-48c8-bfbf-4fe9b3a26d31
  2. cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 64
    Logic
    OR
    Version bounds
    from including 15.1.0; through excluding 15.1.5.1
    Match ID
    7ca80562-dd10-47a8-8a9c-75056d8a81ec
  3. cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 63
    Logic
    OR
    Version bounds
    from including 14.1.0; through excluding 14.1.4.6
    Match ID
    83b25ae8-6158-4448-b096-58105102cd78
  4. cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 65
    Logic
    OR
    Version bounds
    from including 16.1.0; through excluding 16.1.2.2
    Match ID
    3c53d007-b6dd-447e-ba9a-5ce9137caa80
  5. cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 61
    Logic
    OR
    Version bounds
    from including 12.1.0; through including 12.1.6
    Match ID
    9fba5cdc-1989-4971-bd1b-f14e801f5017
  6. cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 62
    Logic
    OR
    Version bounds
    from including 13.1.0; through excluding 13.1.5
    Match ID
    cfe503f5-17e8-4893-aba9-2075180eba82

Affected-product evidence

Accepted scope and product mapping

11 canonical links · 1 source-reported links

Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-000cb533806b78ef860fa6bff163646e9d5756ef6c2d4d7d222692c4cd4c943f

Source class
Nvd cpe vulnerable target
Assertions
6
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
01328c61-2cdc-46b1-8410-74228e87bf6001fd5715-cf7b-47d8-b737-8be0441ce9de7ad59a31-709a-4ba4-8c5b-18011327439e92e3826e-8b97-4084-b2f5-3ef3a8d577e69ec7f77b-d305-46dd-8274-b0a7c5c39c5fdeeffd3e-0d44-4dd1-911b-1c9a286ef73f
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-618e73be1c78cebd98c0451389a4bfe0fed7033b9a99c5dfef4ab081a1711fd0

Source class
Nvd cpe vulnerable target
Assertions
6
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
06978faa-93f7-4951-a201-66bae25e3acc1a00a839-5c4d-4844-9624-78aa906704661a9e6fa8-1afd-41da-8c1a-54ab74b8b2508f48e74f-159a-4793-b30c-4cf7f18ef152a2fb211c-c302-495b-b4ab-299ffedf6e8cda7dc089-e014-4777-833e-786ceab7d39b
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-8754268b8c2cde0fe6aca92689e07534654bf0c32f504fdc7eabdc3dd51c0dab

Source class
Nvd cpe vulnerable target
Assertions
6
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
0b265612-4608-4350-8bba-21614e6984a2588471ed-e407-46b5-ba66-86d6404ae25794c4294c-bd4b-4b1f-a0e6-1d1a09dc0d04aea7de89-cd74-409a-a456-b80f23b1a07add3979f2-c653-4f3f-acc2-b2252db6563ee39755de-c2a7-4f7b-94e0-86da89a08643
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-8f453bafc34e9c461b1290b73550569e7558e64398eede2e74d46d6cb72adae8

Source class
Nvd cpe vulnerable target
Assertions
6
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
02d9dc9d-0956-49e4-a71e-ad2a811d1a472494cd57-f395-4f3b-b073-23849612c0517a06a5e4-f028-4bc2-987d-cd05a16d100aae9a64f3-b8d3-4d02-865f-ec24b417f79dbd84411a-3f75-4394-a0fc-4000d0115929d246cfdf-c45a-4894-8759-f837c7047efd
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-b94ca11deae6f3dbdfe71c801d37911c9fd185c5bd3c37c804c67d15918d47d3

Source class
Nvd cpe vulnerable target
Assertions
6
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
50a1984c-b347-49a1-823a-067d51f6411e59402bb4-376e-45af-86c3-92ebd3b7eb1f64fae85a-935f-4344-bd6a-a60c6f46c2cc8b8e771d-ca5b-455e-9861-2036b53a62678d9873fa-f2bc-43f0-986f-52292a12ec4bc0ef39d4-2f5e-4a6d-a8f4-417f43cd2b3c
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-ba5b29ee89c2340743c5ed2999e757bf44af0086b8b527afdbbe3f8a626803da

Source class
Nvd cpe vulnerable target
Assertions
6
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
286cfd8e-2570-46e2-80e7-397f11040ce9667c4d12-0c56-4bc3-9aaa-745fa21acc7d85b9c29b-96dd-4075-9d9d-3978e4471c308dff3a5e-4acb-4d83-962b-83fb12eb8171af459eb1-9f61-4c41-b722-81d45c5164c2df11e6de-4179-4102-92a2-bcb24f23a7e2
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-bcf09b1e7f256f8ae475f16dc9eb0c89893ad01b1d9c94b66d17ac875578a078

Source class
Nvd cpe vulnerable target
Assertions
6
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
3a00d166-e50f-4b25-9e83-049c4c424b5770a9e80a-bc09-415a-805a-2c0385f3a7537ee47f83-c85e-4ead-a743-86c24ed4f592c30fbfe0-b6cb-4190-b42a-82a439528ccfd9133907-9997-42b2-89a7-b5404def3d77f66d8349-2249-42e8-b053-1e01ce944cce
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-c611bfdeac48cac2141d0aebba0e7ba6ff1c599d72cfe95a76f1db1b7fe68b36

Source class
Nvd cpe vulnerable target
Assertions
6
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
654771de-786e-4b62-9103-44084b94b21f726ff4d3-d6e6-4976-b23c-67b792dfc5a28d8fd097-3063-443c-b2f9-24bd0c758e33c248a2cd-76be-4a5e-b3d2-ff4d5c770d75cc4edba5-3954-4c46-969c-85d7758bd428fc627fe1-760d-498f-a579-f1d0197390cd
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-dfc8c075c3b90f711dd6c07c1d70e2c3507742bbcffef3651f2737a4133eeb81

Source class
Nvd cpe vulnerable target
Assertions
6
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
0b5edfd7-8e13-407e-9e00-d10cdfaab8471cf3afff-0816-46cb-941a-98cad9586e6e2b645948-0ee3-472a-98c4-b9f7782ccdd46952ecf4-bbf3-4f79-afd0-435692833f86b250db3b-6fd1-4907-9a76-a74b35c1fa0bd1f0dc7f-7872-43aa-91f9-d43acbf2979d
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-e23ab53fe98a6d7dc5b97fdacee007e8bb696cfe3231c6ccc001c53853c3209c

Source class
Nvd cpe vulnerable target
Assertions
6
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
13bd86be-4043-478c-8490-7f90eafc4ec4350862b6-7a36-4d07-9d23-08027d21b75d7c3d948e-edcb-4ffb-a3f2-128566c0ae107fa10f6b-f1a4-4d69-80e8-2f94f876962bb5e9400b-402f-448f-aa0c-4869a6895a86c81db3e7-9664-4634-a238-a49b96429e4c
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-fe8f45eed4bb3ac6e69f6f6fbf87e9e25862951e870386e176dca756ebfdb2cb

Source class
Nvd cpe vulnerable target
Assertions
6
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
288af2e9-3991-4904-b8cc-85ecb89a559e3dac8e1e-b027-4df4-8511-2f35ba01bc996cd42f82-5856-4c44-802e-07c2d44c0604acad52f6-224d-4742-a70f-7ce0a0ae3057b19379b2-3771-49ea-bffc-f45118f43b33e1badb6a-22a7-4355-a5be-120c841cefbe
Source-reported scopeSource-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Vendor specified only by source · Product specified only by source

Source class
Direct cve affected
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
89b4a3f4-c8ea-43e8-b792-9ac178e2d038

Assessments

CVSS by origin

7.5
NVDCVSS 2.0 · role Primary · priority eligiblevalid_matchAV:N/AC:L/Au:N/C:P/I:P/A:P
9.8
f5sirt@f5.comCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8
NVDCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8
f5CVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Direct CVE/CNA normalized decisions

9.8Priority eligible

f5

CVSS 3.1 · Primary · Original assertion · rank 1

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Validation
Valid match
Recomputed
9.8
Decision reason
Evidence supported
Policy
casca-direct-cvss-eligibility-v1

Assessments are retained side by side under closed precedence. Cascade never averages CVSS.

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.