Evidence dossier

CVE-2023-46747

BIG-IP Configuration utility unauthenticated remote code execution vulnerability

Exploited in the wild (CISA KEV since Oct 31, 2023). NVD reports CVSS 3.1 9.8. EPSS estimates 96.5% exploit likelihood as of Aug 18, 2026.

91.992.7Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

State
PUBLISHED
Published
Oct 26, 2023
Updated
Oct 21, 2025
Evidence coverage
99%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    f5

    Record text: BIG-IP Configuration utility unauthenticated remote code execution vulnerability

    Inspect raw assertion
    Field
    container
    Value
    BIG-IP Configuration utility unauthenticated remote code execution vulnerability
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability
    Original evidence ↗
  5. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 96.52% probability · 99.88th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.965150000000; percentile 0.998790000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date Oct 31, 2023 · first observed Jul 19, 2026

Exploit likelihood96.52%

FIRST EPSS · score date Aug 18, 2026 · 99.9th percentile · first observed Aug 18, 2026

SeverityCVSS 9.8

NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

casca-unknown-reasons-v1
Exploitation statusEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Exploit likelihoodEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Severity assessmentEvidence supported

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Aug 27, 2026
Resolution
None
Affected productsSource-reported scope

The cited source assertion is retained while canonical product linkage remains open.

Revision
casca-factor-d-obligations-v1
Cutoff
Aug 27, 2026
Resolution
Resolve identity

Source comparison

Who said what

CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
f5Original assertion
Record text

BIG-IP Configuration utility unauthenticated remote code execution vulnerability

Inspect raw assertion
Field
container
Value
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

96.52% probability · 99.88th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.965150000000; percentile 0.998790000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
100Underlying assertions
20Canonical products
100Target assertions
0Constraint assertions

Grouped from 20 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

21 scope groups

f5 · source assertedF5BIG-IPDirect source scope
Affected: 17.1.0 to before * (semver comparison)Affected: 16.1.0 to before * (semver comparison)Affected: 15.1.0 to before * (semver comparison)Affected: 14.1.0 to before * (semver comparison)Affected: 13.1.0 to before * (semver comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "17.1.0", "lessThan": "*", "versionType": "semver"}, {"status": "affected", "version": "16.1.0", "lessThan": "*", "versionType": "semver"}, {"status": "affected", "version": "15.1.0", "lessThan": "*", "versionType": "semver"}, {"status": "affected", "version": "14.1.0", "lessThan": "*", "versionType": "semver"}, {"status": "affected", "version": "13.1.0", "lessThan": "*", "versionType": "semver"}]
NVD CPE · APPLICATIONf5big-ip_access_policy_managerVulnerable target · 5 assertions
Any version (unconstrained) (>= 13.1.0, <= 13.1.5); Any version (unconstrained) (>= 14.1.0, <= 14.1.5); Any version (unconstrained) (>= 15.1.0, <= 15.1.10); Any version (unconstrained) (>= 16.1.0, <= 16.1.4); Any version (unconstrained) (>= 17.1.0, <= 17.1.1)Canonical identity product-fe8f45eed4bb3ac6e69f6f6fbf87e9e25862951e870386e176dca756ebfdb2cbLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 15.1.0; through including 15.1.10
    Match ID
    3a7f605e-eb10-40fb-98d6-7e3a95e310bc
  2. cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 13.1.0; through including 13.1.5
    Match ID
    d93f04ad-df14-48ab-9f13-8b2e491cf42e
  3. cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 14.1.0; through including 14.1.5
    Match ID
    7522c760-7e07-406f-bf50-5656d5723c4f
  4. cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 17.1.0; through including 17.1.1
    Match ID
    db629442-ab06-4552-a7a2-caf967e47c39
  5. cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 16.1.0; through including 16.1.4
    Match ID
    783e62f2-f867-48f1-b123-d1227c970674
NVD CPE · APPLICATIONf5big-ip_advanced_firewall_managerVulnerable target · 5 assertions
Any version (unconstrained) (>= 13.1.0, <= 13.1.5); Any version (unconstrained) (>= 14.1.0, <= 14.1.5); Any version (unconstrained) (>= 15.1.0, <= 15.1.10); Any version (unconstrained) (>= 16.1.0, <= 16.1.4); Any version (unconstrained) (>= 17.1.0, <= 17.1.1)Canonical identity product-c611bfdeac48cac2141d0aebba0e7ba6ff1c599d72cfe95a76f1db1b7fe68b36Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 16.1.0; through including 16.1.4
    Match ID
    d7698d6c-b1f7-43c1-bba6-88e956356b3d
  2. cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 14.1.0; through including 14.1.5
    Match ID
    88978e38-81d3-4efe-8525-a300b101fa69
  3. cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 17.1.0; through including 17.1.1
    Match ID
    e1ea69bc-2aaf-4652-bd2d-95bb754880af
  4. cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 15.1.0; through including 15.1.10
    Match ID
    0510296f-92d7-4388-ae3a-0d9799c2fc4d
  5. cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 13.1.0; through including 13.1.5
    Match ID
    6603ed6a-3366-4572-afcd-b3d4b1ec7606
NVD CPE · APPLICATIONf5big-ip_advanced_web_application_firewallVulnerable target · 5 assertions
Any version (unconstrained) (>= 13.1.0, <= 13.1.5); Any version (unconstrained) (>= 14.1.0, <= 14.1.5); Any version (unconstrained) (>= 15.1.0, <= 15.1.10); Any version (unconstrained) (>= 16.1.0, <= 16.1.4); Any version (unconstrained) (>= 17.1.0, <= 17.1.1)Canonical identity product-3159127811fadcfbf55e58810b397c704a5ecb216e89a6fccc26cab6944674c7Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 17.1.0; through including 17.1.1
    Match ID
    732ce215-90b1-444a-bba4-3ff63d6c63df
  2. cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 15.1.0; through including 15.1.10
    Match ID
    b3c7a168-f370-441e-8790-73014bcec39f
  3. cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 16.1.0; through including 16.1.4
    Match ID
    cf16fd01-7704-40ab-acb2-80a883804d22
  4. cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 14.1.0; through including 14.1.5
    Match ID
    596fc5d5-7329-4e39-841e-cae937c02219
  5. cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 13.1.0; through including 13.1.5
    Match ID
    05e452aa-a520-4cbe-8767-147772b69194
NVD CPE · APPLICATIONf5big-ip_analyticsVulnerable target · 5 assertions
Any version (unconstrained) (>= 13.1.0, <= 13.1.5); Any version (unconstrained) (>= 14.1.0, <= 14.1.5); Any version (unconstrained) (>= 15.1.0, <= 15.1.10); Any version (unconstrained) (>= 16.1.0, <= 16.1.4); Any version (unconstrained) (>= 17.1.0, <= 17.1.1)Canonical identity product-000cb533806b78ef860fa6bff163646e9d5756ef6c2d4d7d222692c4cd4c943fLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    12 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 15.1.0; through including 15.1.10
    Match ID
    8fa85ec1-d91a-49dd-949b-2af7ac813ca5
  2. cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    12 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 16.1.0; through including 16.1.4
    Match ID
    20662bb0-4c3d-4cf0-b068-3555c65dd06c
  3. cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    12 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 17.1.0; through including 17.1.1
    Match ID
    d64edcad-f658-41a9-8838-41a2913ee8b7
  4. cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    12 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 13.1.0; through including 13.1.5
    Match ID
    9167fec1-2c37-4946-9657-b4e69301fb24
  5. cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    12 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 14.1.0; through including 14.1.5
    Match ID
    7b4b3442-e0c0-48cd-87ad-060e15c9801e
NVD CPE · APPLICATIONf5big-ip_application_acceleration_managerVulnerable target · 5 assertions
Any version (unconstrained) (>= 13.1.0, <= 13.1.5); Any version (unconstrained) (>= 14.1.0, <= 14.1.5); Any version (unconstrained) (>= 15.1.0, <= 15.1.10); Any version (unconstrained) (>= 16.1.0, <= 16.1.4); Any version (unconstrained) (>= 17.1.0, <= 17.1.1)Canonical identity product-bcf09b1e7f256f8ae475f16dc9eb0c89893ad01b1d9c94b66d17ac875578a078Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    13 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 14.1.0; through including 14.1.5
    Match ID
    9b88f9d1-b54b-40c7-a18a-26c4a071d7ec
  2. cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    13 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 13.1.0; through including 13.1.5
    Match ID
    7ec2324d-ec8b-41df-88a7-819e53aad0fc
  3. cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    13 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 15.1.0; through including 15.1.10
    Match ID
    c8f39403-c259-4d6f-9e9a-53671017eedb
  4. cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    13 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 17.1.0; through including 17.1.1
    Match ID
    33b4fe55-81a7-41f8-adb8-b0f84c8205c4
  5. cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    13 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 16.1.0; through including 16.1.4
    Match ID
    220f2d38-fa82-45ef-b957-7678c9fedbc1
NVD CPE · APPLICATIONf5big-ip_application_security_managerVulnerable target · 5 assertions
Any version (unconstrained) (>= 13.1.0, <= 13.1.5); Any version (unconstrained) (>= 14.1.0, <= 14.1.5); Any version (unconstrained) (>= 15.1.0, <= 15.1.10); Any version (unconstrained) (>= 16.1.0, <= 16.1.4); Any version (unconstrained) (>= 17.1.0, <= 17.1.1)Canonical identity product-ba5b29ee89c2340743c5ed2999e757bf44af0086b8b527afdbbe3f8a626803daLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    11 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 14.1.0; through including 14.1.5
    Match ID
    f938eb43-8373-47eb-b269-c6df058a9244
  2. cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    11 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 13.1.0; through including 13.1.5
    Match ID
    922aa845-530a-4b4b-9976-4cbc30c8a324
  3. cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    11 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 16.1.0; through including 16.1.4
    Match ID
    5e86f3d5-65a4-48ce-a6a2-736bbb88e3f8
  4. cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    11 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 17.1.0; through including 17.1.1
    Match ID
    31c4d96a-6d71-44b5-8b94-ae9dfa93873b
  5. cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    11 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 15.1.0; through including 15.1.10
    Match ID
    1771493e-acaa-477f-8ab4-25db12f6ad6e
NVD CPE · APPLICATIONf5big-ip_application_visibility_and_reportingVulnerable target · 5 assertions
Any version (unconstrained) (>= 13.1.0, <= 13.1.5); Any version (unconstrained) (>= 14.1.0, <= 14.1.5); Any version (unconstrained) (>= 15.1.0, <= 15.1.10); Any version (unconstrained) (>= 16.1.0, <= 16.1.4); Any version (unconstrained) (>= 17.1.0, <= 17.1.1)Canonical identity product-e7831dd1502c92cf4956b2496298fff48f6f919ba0502487bde1ee5ad5c98016Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_application_visibility_and_reporting:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    14 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 15.1.0; through including 15.1.10
    Match ID
    4b9b76a1-7c5a-453f-a4ed-f1a81bcebeb5
  2. cpe:2.3:a:f5:big-ip_application_visibility_and_reporting:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    14 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 14.1.0; through including 14.1.5
    Match ID
    cc3f710f-dbcb-4976-9719-cf063da22377
  3. cpe:2.3:a:f5:big-ip_application_visibility_and_reporting:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    14 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 17.1.0; through including 17.1.1
    Match ID
    8c61e3e7-c594-40d9-936a-19cd26b170e6
  4. cpe:2.3:a:f5:big-ip_application_visibility_and_reporting:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    14 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 16.1.0; through including 16.1.4
    Match ID
    88edfcd9-775c-48fa-9cda-2b04da8d0612
  5. cpe:2.3:a:f5:big-ip_application_visibility_and_reporting:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    14 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 13.1.0; through including 13.1.5
    Match ID
    c7e422f6-c4c2-43ac-b137-0997b5739030
NVD CPE · APPLICATIONf5big-ip_automation_toolchainVulnerable target · 5 assertions
Any version (unconstrained) (>= 13.1.0, <= 13.1.5); Any version (unconstrained) (>= 14.1.0, <= 14.1.5); Any version (unconstrained) (>= 15.1.0, <= 15.1.10); Any version (unconstrained) (>= 16.1.0, <= 16.1.4); Any version (unconstrained) (>= 17.1.0, <= 17.1.1)Canonical identity product-b499054f70813299757594ac36607b49f4bcc0b7683d3f39d7ade03e99013f19Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_automation_toolchain:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    9 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 16.1.0; through including 16.1.4
    Match ID
    caa278ba-b020-4bed-91da-1cd8966512d6
  2. cpe:2.3:a:f5:big-ip_automation_toolchain:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    9 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 14.1.0; through including 14.1.5
    Match ID
    3d33aa82-3ae5-4165-9b54-8c03381d98ad
  3. cpe:2.3:a:f5:big-ip_automation_toolchain:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    9 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 15.1.0; through including 15.1.10
    Match ID
    56800e2e-119d-468b-b407-9cfacd8c00d7
  4. cpe:2.3:a:f5:big-ip_automation_toolchain:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    9 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 17.1.0; through including 17.1.1
    Match ID
    e874dd74-e654-44ee-a1a3-57d7ca772fb1
  5. cpe:2.3:a:f5:big-ip_automation_toolchain:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    9 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 13.1.0; through including 13.1.5
    Match ID
    89ada880-7a5b-49da-aea4-bc19d7c41916
NVD CPE · APPLICATIONf5big-ip_carrier-grade_natVulnerable target · 5 assertions
Any version (unconstrained) (>= 13.1.0, <= 13.1.5); Any version (unconstrained) (>= 14.1.0, <= 14.1.5); Any version (unconstrained) (>= 15.1.0, <= 15.1.10); Any version (unconstrained) (>= 16.1.0, <= 16.1.4); Any version (unconstrained) (>= 17.1.0, <= 17.1.1)Canonical identity product-b655dc8d5b821afddbd8d93fa9489ee15a0d676811bd45d3730fe3b26cdd735dLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_carrier-grade_nat:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 17.1.0; through including 17.1.1
    Match ID
    c640fa3f-7ab7-4875-b01d-9db41ceb432b
  2. cpe:2.3:a:f5:big-ip_carrier-grade_nat:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 15.1.0; through including 15.1.10
    Match ID
    db704a1c-d8b7-48bb-a15a-c14db591fe4a
  3. cpe:2.3:a:f5:big-ip_carrier-grade_nat:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 14.1.0; through including 14.1.5
    Match ID
    112dfa85-90ad-478d-bd70-8c7c0c074f1b
  4. cpe:2.3:a:f5:big-ip_carrier-grade_nat:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 16.1.0; through including 16.1.4
    Match ID
    21d51d9f-2840-4dea-a007-d20111a1745c
  5. cpe:2.3:a:f5:big-ip_carrier-grade_nat:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 13.1.0; through including 13.1.5
    Match ID
    4c9fcbcb-9ce0-49e7-85c8-69e71d211912
NVD CPE · APPLICATIONf5big-ip_container_ingress_servicesVulnerable target · 5 assertions
Any version (unconstrained) (>= 13.1.0, <= 13.1.5); Any version (unconstrained) (>= 14.1.0, <= 14.1.5); Any version (unconstrained) (>= 15.1.0, <= 15.1.10); Any version (unconstrained) (>= 16.1.0, <= 16.1.4); Any version (unconstrained) (>= 17.1.0, <= 17.1.1)Canonical identity product-5baa90dcb54b8e683bcfbe334e0b18cbe8ea2d032eb45cd55f7afcfa9da03368Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_container_ingress_services:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    10 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 14.1.0; through including 14.1.5
    Match ID
    5630f852-7110-4332-95df-2d34365ba076
  2. cpe:2.3:a:f5:big-ip_container_ingress_services:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    10 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 16.1.0; through including 16.1.4
    Match ID
    3095b6f6-c2ff-44b2-97aa-eef5f475a608
  3. cpe:2.3:a:f5:big-ip_container_ingress_services:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    10 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 13.1.0; through including 13.1.5
    Match ID
    5d87ee02-c9af-4824-bab1-5f674c51d78e
  4. cpe:2.3:a:f5:big-ip_container_ingress_services:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    10 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 17.1.0; through including 17.1.1
    Match ID
    437ca326-41b9-4dbd-93b6-1ff93f5eafce
  5. cpe:2.3:a:f5:big-ip_container_ingress_services:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    10 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 15.1.0; through including 15.1.10
    Match ID
    425a5d8f-c719-459f-8ff4-fc3efb4b6bb3
NVD CPE · APPLICATIONf5big-ip_ddos_hybrid_defenderVulnerable target · 5 assertions
Any version (unconstrained) (>= 13.1.0, <= 13.1.5); Any version (unconstrained) (>= 14.1.0, <= 14.1.5); Any version (unconstrained) (>= 15.1.0, <= 15.1.10); Any version (unconstrained) (>= 16.1.0, <= 16.1.4); Any version (unconstrained) (>= 17.1.0, <= 17.1.1)Canonical identity product-f87c7b9b64c86afcc0c48220bda1bc92543beefff7155621fe458a2627cfe653Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 14.1.0; through including 14.1.5
    Match ID
    2fbce2d1-9d93-415d-ab2c-2060307c305a
  2. cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 16.1.0; through including 16.1.4
    Match ID
    a326597e-725d-45de-bef7-2ed92137b253
  3. cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 13.1.0; through including 13.1.5
    Match ID
    caef3ea4-7d5a-4b44-9ce3-258aec745866
  4. cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 15.1.0; through including 15.1.10
    Match ID
    8070b469-8cc4-4d2f-97d7-12d0abb963c1
  5. cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 17.1.0; through including 17.1.1
    Match ID
    7479843e-f2d9-4815-95bc-f4223119753c
NVD CPE · APPLICATIONf5big-ip_domain_name_systemVulnerable target · 5 assertions
Any version (unconstrained) (>= 13.1.0, <= 13.1.5); Any version (unconstrained) (>= 14.1.0, <= 14.1.5); Any version (unconstrained) (>= 15.1.0, <= 15.1.10); Any version (unconstrained) (>= 16.1.0, <= 16.1.4); Any version (unconstrained) (>= 17.1.0, <= 17.1.1)Canonical identity product-8f453bafc34e9c461b1290b73550569e7558e64398eede2e74d46d6cb72adae8Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 13.1.0; through including 13.1.5
    Match ID
    08b25aab-a98c-4f89-9131-29e3a8c0ed23
  2. cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 14.1.0; through including 14.1.5
    Match ID
    ed9b976a-d3ad-4445-bf8a-067c3ebdfbb0
  3. cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 17.1.0; through including 17.1.1
    Match ID
    375d359b-e05b-4aec-9b39-46911847a410
  4. cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 15.1.0; through including 15.1.10
    Match ID
    98d2ce1e-ded0-470a-aa78-c78ef769c38e
  5. cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 16.1.0; through including 16.1.4
    Match ID
    c966faba-7199-4f0d-ab8c-4590fe9d2fff
NVD CPE · APPLICATIONf5big-ip_fraud_protection_servicesVulnerable target · 5 assertions
Any version (unconstrained) (>= 13.1.0, <= 13.1.5); Any version (unconstrained) (>= 14.1.0, <= 14.1.5); Any version (unconstrained) (>= 15.1.0, <= 15.1.10); Any version (unconstrained) (>= 16.1.0, <= 16.1.4); Any version (unconstrained) (>= 17.1.0, <= 17.1.1)Canonical identity product-ec18136a1fd9c7ae5d975d2a2f5c0037e57c749e49c0715b9b8a25d6f0ee853dLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_fraud_protection_services:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    15 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 17.1.0; through including 17.1.1
    Match ID
    b84c35ad-d355-4db4-99f1-6eba2d91f322
  2. cpe:2.3:a:f5:big-ip_fraud_protection_services:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    15 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 15.1.0; through including 15.1.10
    Match ID
    958c34e5-668d-416a-99af-2c6f042a2215
  3. cpe:2.3:a:f5:big-ip_fraud_protection_services:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    15 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 16.1.0; through including 16.1.4
    Match ID
    659376e8-fcca-45e1-bdfb-c50117a66484
  4. cpe:2.3:a:f5:big-ip_fraud_protection_services:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    15 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 14.1.0; through including 14.1.5
    Match ID
    00deabfc-139a-4306-bcfa-6ce700d64327
  5. cpe:2.3:a:f5:big-ip_fraud_protection_services:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    15 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 13.1.0; through including 13.1.5
    Match ID
    84d9cd72-ed25-4447-9dd5-41ed51c891e5
NVD CPE · APPLICATIONf5big-ip_global_traffic_managerVulnerable target · 5 assertions
Any version (unconstrained) (>= 13.1.0, <= 13.1.5); Any version (unconstrained) (>= 14.1.0, <= 14.1.5); Any version (unconstrained) (>= 15.1.0, <= 15.1.10); Any version (unconstrained) (>= 16.1.0, <= 16.1.4); Any version (unconstrained) (>= 17.1.0, <= 17.1.1)Canonical identity product-618e73be1c78cebd98c0451389a4bfe0fed7033b9a99c5dfef4ab081a1711fd0Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    16 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 15.1.0; through including 15.1.10
    Match ID
    5d2a121f-5bd2-4263-8ed3-1dde25b5c306
  2. cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    16 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 17.1.0; through including 17.1.1
    Match ID
    df43cd3a-2c94-4663-b5d5-0327fd3e1f3d
  3. cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    16 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 13.1.0; through including 13.1.5
    Match ID
    e6018b01-048c-43bb-a78d-66910ed60ca9
  4. cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    16 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 14.1.0; through including 14.1.5
    Match ID
    3a6a5686-5a8b-45d5-9165-bc99d2ccac47
  5. cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    16 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 16.1.0; through including 16.1.4
    Match ID
    0a4f7bad-3edd-4de0-aab7-de5aca34dd79
NVD CPE · APPLICATIONf5big-ip_link_controllerVulnerable target · 5 assertions
Any version (unconstrained) (>= 13.1.0, <= 13.1.5); Any version (unconstrained) (>= 14.1.0, <= 14.1.5); Any version (unconstrained) (>= 15.1.0, <= 15.1.10); Any version (unconstrained) (>= 16.1.0, <= 16.1.4); Any version (unconstrained) (>= 17.1.0, <= 17.1.1)Canonical identity product-8754268b8c2cde0fe6aca92689e07534654bf0c32f504fdc7eabdc3dd51c0dabLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    17 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 15.1.0; through including 15.1.10
    Match ID
    29563719-1af2-4bb8-8cca-a0869f87795d
  2. cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    17 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 14.1.0; through including 14.1.5
    Match ID
    f70d4b6f-65cf-48f4-9a07-072dfbce53d9
  3. cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    17 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 16.1.0; through including 16.1.4
    Match ID
    d24815dd-579a-46d1-b9f2-3bb2c56bc54d
  4. cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    17 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 13.1.0; through including 13.1.5
    Match ID
    d9ec2237-117f-43bd-adec-516cf72e04ef
  5. cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    17 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 17.1.0; through including 17.1.1
    Match ID
    95c1f4f7-7533-44ce-be4c-bf71eafa62ea
NVD CPE · APPLICATIONf5big-ip_local_traffic_managerVulnerable target · 5 assertions
Any version (unconstrained) (>= 13.1.0, <= 13.1.5); Any version (unconstrained) (>= 14.1.0, <= 14.1.5); Any version (unconstrained) (>= 15.1.0, <= 15.1.10); Any version (unconstrained) (>= 16.1.0, <= 16.1.4); Any version (unconstrained) (>= 17.1.0, <= 17.1.1)Canonical identity product-dfc8c075c3b90f711dd6c07c1d70e2c3507742bbcffef3651f2737a4133eeb81Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 17.1.0; through including 17.1.1
    Match ID
    820076a8-f163-4471-8b1e-5290bd1d6d93
  2. cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 15.1.0; through including 15.1.10
    Match ID
    441cc945-7ca3-49c0-ae10-94725301e31d
  3. cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 16.1.0; through including 16.1.4
    Match ID
    46ba8e8a-6ed5-4fb2-8bbc-586aa031085a
  4. cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 13.1.0; through including 13.1.5
    Match ID
    0360f76d-e75e-4b05-a294-b47012323ed9
  5. cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 14.1.0; through including 14.1.5
    Match ID
    7a4607bf-41ac-4e84-a110-74e085ff0445
NVD CPE · APPLICATIONf5big-ip_policy_enforcement_managerVulnerable target · 5 assertions
Any version (unconstrained) (>= 13.1.0, <= 13.1.5); Any version (unconstrained) (>= 14.1.0, <= 14.1.5); Any version (unconstrained) (>= 15.1.0, <= 15.1.10); Any version (unconstrained) (>= 16.1.0, <= 16.1.4); Any version (unconstrained) (>= 17.1.0, <= 17.1.1)Canonical identity product-b94ca11deae6f3dbdfe71c801d37911c9fd185c5bd3c37c804c67d15918d47d3Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    8 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 17.1.0; through including 17.1.1
    Match ID
    17523f89-df78-45b7-aeab-a4886e99e08b
  2. cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    8 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 16.1.0; through including 16.1.4
    Match ID
    910441d3-90ef-4375-b007-d51120a60ab2
  3. cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    8 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 15.1.0; through including 15.1.10
    Match ID
    fff5007e-761c-4697-8d34-c064df0abe8d
  4. cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    8 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 14.1.0; through including 14.1.5
    Match ID
    37db32bb-f4ba-4fb5-94b1-55c3f06749cf
  5. cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    8 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 13.1.0; through including 13.1.5
    Match ID
    8257aa59-c14d-4ec1-b22c-dfbb92cbc297
NVD CPE · APPLICATIONf5big-ip_ssl_orchestratorVulnerable target · 5 assertions
Any version (unconstrained) (>= 13.1.0, <= 13.1.5); Any version (unconstrained) (>= 14.1.0, <= 14.1.5); Any version (unconstrained) (>= 15.1.0, <= 15.1.10); Any version (unconstrained) (>= 16.1.0, <= 16.1.4); Any version (unconstrained) (>= 17.1.0, <= 17.1.1)Canonical identity product-1f7d291882e58db33699a4631d94b94ac47c4054e89f4ab9ba55e10df6020b64Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_ssl_orchestrator:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 14.1.0; through including 14.1.5
    Match ID
    5a90f547-97a2-41ec-9fdf-25f869f0fa38
  2. cpe:2.3:a:f5:big-ip_ssl_orchestrator:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 13.1.0; through including 13.1.5
    Match ID
    8a6f9699-a485-4614-8f38-5a556d31617e
  3. cpe:2.3:a:f5:big-ip_ssl_orchestrator:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 17.1.0; through including 17.1.1
    Match ID
    25e7dbe6-d708-4257-ba8b-90a4db6de1ea
  4. cpe:2.3:a:f5:big-ip_ssl_orchestrator:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 15.1.0; through including 15.1.10
    Match ID
    e76e1b82-f1dc-4366-b388-dbdf16c586a0
  5. cpe:2.3:a:f5:big-ip_ssl_orchestrator:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 16.1.0; through including 16.1.4
    Match ID
    660137f4-15a1-42d1-bbac-99a1d5bb398b
NVD CPE · APPLICATIONf5big-ip_webacceleratorVulnerable target · 5 assertions
Any version (unconstrained) (>= 13.1.0, <= 13.1.5); Any version (unconstrained) (>= 14.1.0, <= 14.1.5); Any version (unconstrained) (>= 15.1.0, <= 15.1.10); Any version (unconstrained) (>= 16.1.0, <= 16.1.4); Any version (unconstrained) (>= 17.1.0, <= 17.1.1)Canonical identity product-9a98c46bb3d6ba9611bd32eab93edabd599af91bf31121c045dc220d5c65e47bLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    18 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 16.1.0; through including 16.1.4
    Match ID
    3a599f90-f66b-4df0-ad7d-d234f328bd59
  2. cpe:2.3:a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    18 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 15.1.0; through including 15.1.10
    Match ID
    2cd1637d-0e42-4928-867a-ba0fdb6e8462
  3. cpe:2.3:a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    18 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 13.1.0; through including 13.1.5
    Match ID
    1932d32d-0e4b-4bbd-816f-6d47ab2e2f04
  4. cpe:2.3:a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    18 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 14.1.0; through including 14.1.5
    Match ID
    d47b7691-a95b-45c0-bab4-27e047f3c379
  5. cpe:2.3:a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    18 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 17.1.0; through including 17.1.1
    Match ID
    609593ad-6e6d-4b8d-b01b-ef4768e8df10
NVD CPE · APPLICATIONf5big-ip_websafeVulnerable target · 5 assertions
Any version (unconstrained) (>= 13.1.0, <= 13.1.5); Any version (unconstrained) (>= 14.1.0, <= 14.1.5); Any version (unconstrained) (>= 15.1.0, <= 15.1.10); Any version (unconstrained) (>= 16.1.0, <= 16.1.4); Any version (unconstrained) (>= 17.1.0, <= 17.1.1)Canonical identity product-59c1a99b28f4b9b4655fbcd860d02e1150ce2f13239c2e93385600c2666878baLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_websafe:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    19 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 13.1.0; through including 13.1.5
    Match ID
    5326759a-afb0-4a15-b4e9-3c9a2e5db32a
  2. cpe:2.3:a:f5:big-ip_websafe:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    19 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 15.1.0; through including 15.1.10
    Match ID
    eccb8c30-861e-4e48-a5f5-30ee523c1fb6
  3. cpe:2.3:a:f5:big-ip_websafe:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    19 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 14.1.0; through including 14.1.5
    Match ID
    57d92d05-c67d-437e-88f3-dcc3f6b0ed2f
  4. cpe:2.3:a:f5:big-ip_websafe:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    19 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 16.1.0; through including 16.1.4
    Match ID
    f5fead2a-3a58-432e-bebb-6e3fde24395f
  5. cpe:2.3:a:f5:big-ip_websafe:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    19 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 17.1.0; through including 17.1.1
    Match ID
    2044d97e-5637-45ba-a004-a717b5e793fd

Affected-product evidence

Accepted scope and product mapping

20 canonical links · 1 source-reported links

Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-000cb533806b78ef860fa6bff163646e9d5756ef6c2d4d7d222692c4cd4c943f

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
00ed7f1a-e52a-4978-9139-bfcd80ddc03657d6f7f3-41f2-4d8d-af52-e6219707e31668453bfc-c6dd-4912-8f29-f10ed347f3ffa5f8d02b-980d-469f-a3b6-200ef2d58f94b12def9f-1926-4d93-8cb3-cb4986e20421
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-1f7d291882e58db33699a4631d94b94ac47c4054e89f4ab9ba55e10df6020b64

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
1262a2db-bc61-40cc-a39c-f29aa83bcf63187517d4-48fd-4b54-8768-503d6c59d64e28595fc1-f7d0-494e-a6e5-16180952ab35eb6b4968-a2a4-4d8d-a836-30b40582b1dbfce28d8a-125b-4cbb-b86a-8c3004577bdf
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-3159127811fadcfbf55e58810b397c704a5ecb216e89a6fccc26cab6944674c7

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
2be0cda0-a649-4a3c-812f-c70b61957e175453028d-f80e-4ee1-accd-80468ab6991d5eb22481-005a-42bb-8e91-604d7ec2e391e087e22c-5689-4530-9840-7cdd0264ad66fc7f11ae-ac89-43e6-9c7a-c0255668e8ba
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-59c1a99b28f4b9b4655fbcd860d02e1150ce2f13239c2e93385600c2666878ba

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
34a0abaf-e72c-4e7c-9693-094e6532c0563d522c8b-5454-4a7d-8ed1-9eaf9c3b0d4461615b84-140f-4dbe-9567-734a6c0357ff8c2fb8a0-6d93-46e9-a151-e180b6f83346c9c031b0-1bb8-4667-884a-ccaf16a8316c
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-5baa90dcb54b8e683bcfbe334e0b18cbe8ea2d032eb45cd55f7afcfa9da03368

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
064a138c-8ea5-4a74-a9d6-d6ad81fcae4f163f7db1-d4f0-4954-8500-f8c6c6e04b0ea23dead9-749e-4a29-91dc-dee78c868c69aeb93045-dc30-43be-9f54-9314a35b4b30b5876551-fbbc-455d-b9e9-440aaed0c2d2
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-618e73be1c78cebd98c0451389a4bfe0fed7033b9a99c5dfef4ab081a1711fd0

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
18104f83-c0ea-4bb8-af1f-99c03311c2ef1db9beb2-ad8a-4cfd-812d-73f0ae2fafbb74364eab-d564-4aa9-9fa1-9807bed99f83c414dbe3-b8a8-45b0-917e-5546e6d08caee0bdf0d5-6e27-4ec9-b17f-5247d3d4cbc7
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-8754268b8c2cde0fe6aca92689e07534654bf0c32f504fdc7eabdc3dd51c0dab

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
23c4981f-3fd1-46d5-82a5-0699c31508c15fdb5849-75b2-43dd-83f6-5bf15bc32356abd2c627-57c1-41ae-b1ff-f0c43e41d9b0b56b5e68-082b-4a30-b361-48de92af04fdc8d97d1f-7d66-48b7-9543-bcac348b9bbe
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-8f453bafc34e9c461b1290b73550569e7558e64398eede2e74d46d6cb72adae8

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
0157ad33-21b2-4df3-9913-45de9c2d6b4505193650-13e8-476e-9409-7734b59aaa2f6a091e46-e732-4487-960f-ccfc6a3257f66a916237-6c9c-4f2d-9477-1c2c433409ccc9fe8a97-1f27-4f44-9dc8-8d9d614f1679
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-9a98c46bb3d6ba9611bd32eab93edabd599af91bf31121c045dc220d5c65e47b

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
311fd92d-d746-4483-aebf-f9c584085053362be2d7-980c-4fa5-bd9d-cc567c98e9ab36528c50-d14a-4f24-92ad-cc8a1f4a2f7d82a9f4de-2431-430b-9691-b0061a53d6b7f5288a5e-1e6f-473b-b2ec-62161bd31091
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-b499054f70813299757594ac36607b49f4bcc0b7683d3f39d7ade03e99013f19

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
848709ca-5f59-413e-a103-b90c80d17e5a8c585866-be7b-4c15-9799-df98c10480ac90c9d50c-9c6d-44d3-812a-6baef31fc3f3e05ab27f-150f-4cdf-a01f-d0fbad7b7ee9f23e617c-e0b5-4d2e-9f79-dbef78869c75
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-b655dc8d5b821afddbd8d93fa9489ee15a0d676811bd45d3730fe3b26cdd735d

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
1d9820bd-db00-4f22-98eb-85d4247fc0b16acc16b5-9041-4b91-ae12-3c74633926de9aeecfa6-d221-4176-a0d6-27e8901ed3789fd32448-0d20-4fc2-bb20-4f1e466d76c2ad211629-8336-4513-8fbf-cf2c41c29900
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-b94ca11deae6f3dbdfe71c801d37911c9fd185c5bd3c37c804c67d15918d47d3

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
0d7e3962-f3e0-4687-828a-752c56d641bd47f8346e-1fb9-49f6-a66d-89421ffeea878ef52e78-ab6f-4657-ae56-ff58896e99bbad6ec350-a082-4754-b388-73b0d5b0bde6d40f8a2c-e5d5-4a51-8314-793b54127e95
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-ba5b29ee89c2340743c5ed2999e757bf44af0086b8b527afdbbe3f8a626803da

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
0836dbe1-4dc8-428f-8963-3b96f11ca3856cf18904-591e-46d2-9ac1-3530cdc1f953c332e6eb-d26e-4a2d-bc27-2d055306a632d2e40797-a39c-471b-b6f2-52ecc516bca2d412fe44-8cf9-4664-bbd8-85c4e15c61b4
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-bcf09b1e7f256f8ae475f16dc9eb0c89893ad01b1d9c94b66d17ac875578a078

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
3d0fbd99-0a5d-4594-a9d8-65de99e7f76a472499f6-5a6a-47f1-a0c6-c6405afc3da8960427ed-549b-4d13-9f10-d32a053da9c2ca1696ef-c5f2-497c-912a-88ed67f9d51cd4408387-1d28-47c3-935d-e293ae8a5ac5
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-c611bfdeac48cac2141d0aebba0e7ba6ff1c599d72cfe95a76f1db1b7fe68b36

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
a80bca0d-09bc-4c56-8f9d-1500606195b6b823c9a9-252a-4fcf-bc5a-84c0b21d3337bdb26d31-9d45-40f7-95e4-2360b9502455c0db41f4-ad71-475f-b741-7b85c3394cf2cee9afef-542c-4433-ac71-ed47d66b68f3
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-dfc8c075c3b90f711dd6c07c1d70e2c3507742bbcffef3651f2737a4133eeb81

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
2b4b6a5e-4357-40cb-a7db-403e3dc2191653e9b0a9-9ff3-4fc6-925b-106c731a4341613c1faf-897f-4bc8-8f8b-9726b96ccb4489b83fc5-cf6c-484a-9b49-952d912e3ef08f17e73d-0f3b-4b37-962e-1887aad7496f
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-e7831dd1502c92cf4956b2496298fff48f6f919ba0502487bde1ee5ad5c98016

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
0e10ae35-e6b3-4711-8a66-3d8b29266efd1d24391b-8a3d-427b-bf75-32b04ccbeb2b5b1c639f-202a-4ab9-80c6-862b61d468cac3718d3f-a30f-408f-b314-5dba0b9cf5d6d6e92444-ba79-44f6-be27-40aa7cdb3644
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-ec18136a1fd9c7ae5d975d2a2f5c0037e57c749e49c0715b9b8a25d6f0ee853d

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
29817582-dcae-4c38-a60c-717386d612254a01298b-8eff-4beb-8699-e0a1cdbeb83f529dd392-9bd4-4db7-99d4-4e0b2d53df6d8ab9e284-e20a-4738-8602-a8caf3aa74bdc8977499-5981-42b7-85ba-bbd3cdbbea58
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-f87c7b9b64c86afcc0c48220bda1bc92543beefff7155621fe458a2627cfe653

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
5c25054e-637c-4881-ada7-ac209d52d642807df8a5-b321-4b34-920b-3b0f507c8cb4cda6dce3-5662-4479-9dc5-2677d868113bd96e02b2-dc2c-4956-ab20-62440313c5a1ff2ee63b-bf20-49ae-8416-6f832401a413
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-fe8f45eed4bb3ac6e69f6f6fbf87e9e25862951e870386e176dca756ebfdb2cb

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
2a88f292-8735-48ce-a07d-8be7bc4669243ab2f35b-e41b-4996-89c7-61c656301fb96727a19e-ea47-46cf-a7fc-4de13bb044587444a6e7-ce2a-430a-88df-dd9af1fdcccbf4198440-c2f5-4fa0-b93d-bdd3d4eb0d41
Source-reported scopeSource-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Vendor specified only by source · Product specified only by source

Source class
Direct cve affected
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
25d7c1de-2774-4f12-b0f4-074ca8965655

Assessments

CVSS by origin

9.8
NVDCVSS 3.1 · role Primary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8
f5sirt@f5.comCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8
f5CVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Direct CVE/CNA normalized decisions

9.8Priority eligible

f5

CVSS 3.1 · Primary · Original assertion · rank 1

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Validation
Valid match
Recomputed
9.8
Decision reason
Evidence supported
Policy
casca-direct-cvss-eligibility-v1

Assessments are retained side by side under closed precedence. Cascade never averages CVSS.

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.