Evidence dossier

CVE-2023-46748

BIG-IP Configuration utility authenticated SQL injection vulnerability

Exploited in the wild (CISA KEV since Oct 31, 2023). NVD reports CVSS 3.1 8.8. EPSS estimates 4.5% exploit likelihood as of Aug 27, 2026.

74.074.7Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

State
PUBLISHED
Published
Oct 26, 2023
Updated
Oct 21, 2025
Evidence coverage
99%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    f5

    Record text: BIG-IP Configuration utility authenticated SQL injection vulnerability

    Inspect raw assertion
    Field
    container
    Value
    BIG-IP Configuration utility authenticated SQL injection vulnerability
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: F5 BIG-IP Configuration Utility SQL Injection Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    F5 BIG-IP Configuration Utility SQL Injection Vulnerability
    Original evidence ↗
  5. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 4.47% probability · 90.73th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.044680000000; percentile 0.907330000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date Oct 31, 2023 · first observed Jul 19, 2026

Exploit likelihood4.47%

FIRST EPSS · score date Aug 27, 2026 · 90.7th percentile · first observed Aug 27, 2026

SeverityCVSS 8.8

NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

casca-unknown-reasons-v1
Exploitation statusEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Exploit likelihoodEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Severity assessmentEvidence supported

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Aug 27, 2026
Resolution
None
Affected productsSource-reported scope

The cited source assertion is retained while canonical product linkage remains open.

Revision
casca-factor-d-obligations-v1
Cutoff
Aug 27, 2026
Resolution
Resolve identity

Source comparison

Who said what

CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
f5Original assertion
Record text

BIG-IP Configuration utility authenticated SQL injection vulnerability

Inspect raw assertion
Field
container
Value
BIG-IP Configuration utility authenticated SQL injection vulnerability
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

F5 BIG-IP Configuration Utility SQL Injection Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
F5 BIG-IP Configuration Utility SQL Injection Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

4.47% probability · 90.73th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.044680000000; percentile 0.907330000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
100Underlying assertions
20Canonical products
100Target assertions
0Constraint assertions

Grouped from 20 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

21 scope groups

f5 · source assertedF5BIG-IPDirect source scope
Affected: 17.1.0 to before * (semver comparison)Affected: 16.1.0 to before * (semver comparison)Affected: 15.1.0 to before * (semver comparison)Affected: 14.1.0 to before * (semver comparison)Affected: 13.1.0 to before * (semver comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "17.1.0", "lessThan": "*", "versionType": "semver"}, {"status": "affected", "version": "16.1.0", "lessThan": "*", "versionType": "semver"}, {"status": "affected", "version": "15.1.0", "lessThan": "*", "versionType": "semver"}, {"status": "affected", "version": "14.1.0", "lessThan": "*", "versionType": "semver"}, {"status": "affected", "version": "13.1.0", "lessThan": "*", "versionType": "semver"}]
NVD CPE · APPLICATIONf5big-ip_access_policy_managerVulnerable target · 5 assertions
Any version (unconstrained) (>= 13.1.0, <= 13.1.5); Any version (unconstrained) (>= 14.1.0, <= 14.1.5); Any version (unconstrained) (>= 15.1.0, <= 15.1.10); Any version (unconstrained) (>= 16.1.0, <= 16.1.4); Any version (unconstrained) (>= 17.1.0, <= 17.1.1)Canonical identity product-fe8f45eed4bb3ac6e69f6f6fbf87e9e25862951e870386e176dca756ebfdb2cbLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 13.1.0; through including 13.1.5
    Match ID
    d93f04ad-df14-48ab-9f13-8b2e491cf42e
  2. cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 14.1.0; through including 14.1.5
    Match ID
    7522c760-7e07-406f-bf50-5656d5723c4f
  3. cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 17.1.0; through including 17.1.1
    Match ID
    db629442-ab06-4552-a7a2-caf967e47c39
  4. cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 16.1.0; through including 16.1.4
    Match ID
    783e62f2-f867-48f1-b123-d1227c970674
  5. cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 15.1.0; through including 15.1.10
    Match ID
    3a7f605e-eb10-40fb-98d6-7e3a95e310bc
NVD CPE · APPLICATIONf5big-ip_advanced_firewall_managerVulnerable target · 5 assertions
Any version (unconstrained) (>= 13.1.0, <= 13.1.5); Any version (unconstrained) (>= 14.1.0, <= 14.1.5); Any version (unconstrained) (>= 15.1.0, <= 15.1.10); Any version (unconstrained) (>= 16.1.0, <= 16.1.4); Any version (unconstrained) (>= 17.1.0, <= 17.1.1)Canonical identity product-c611bfdeac48cac2141d0aebba0e7ba6ff1c599d72cfe95a76f1db1b7fe68b36Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 17.1.0; through including 17.1.1
    Match ID
    e1ea69bc-2aaf-4652-bd2d-95bb754880af
  2. cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 14.1.0; through including 14.1.5
    Match ID
    88978e38-81d3-4efe-8525-a300b101fa69
  3. cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 16.1.0; through including 16.1.4
    Match ID
    d7698d6c-b1f7-43c1-bba6-88e956356b3d
  4. cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 15.1.0; through including 15.1.10
    Match ID
    0510296f-92d7-4388-ae3a-0d9799c2fc4d
  5. cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 13.1.0; through including 13.1.5
    Match ID
    6603ed6a-3366-4572-afcd-b3d4b1ec7606
NVD CPE · APPLICATIONf5big-ip_advanced_web_application_firewallVulnerable target · 5 assertions
Any version (unconstrained) (>= 13.1.0, <= 13.1.5); Any version (unconstrained) (>= 14.1.0, <= 14.1.5); Any version (unconstrained) (>= 15.1.0, <= 15.1.10); Any version (unconstrained) (>= 16.1.0, <= 16.1.4); Any version (unconstrained) (>= 17.1.0, <= 17.1.1)Canonical identity product-3159127811fadcfbf55e58810b397c704a5ecb216e89a6fccc26cab6944674c7Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    9 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 16.1.0; through including 16.1.4
    Match ID
    cf16fd01-7704-40ab-acb2-80a883804d22
  2. cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    9 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 17.1.0; through including 17.1.1
    Match ID
    732ce215-90b1-444a-bba4-3ff63d6c63df
  3. cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    9 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 15.1.0; through including 15.1.10
    Match ID
    b3c7a168-f370-441e-8790-73014bcec39f
  4. cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    9 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 14.1.0; through including 14.1.5
    Match ID
    596fc5d5-7329-4e39-841e-cae937c02219
  5. cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    9 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 13.1.0; through including 13.1.5
    Match ID
    05e452aa-a520-4cbe-8767-147772b69194
NVD CPE · APPLICATIONf5big-ip_analyticsVulnerable target · 5 assertions
Any version (unconstrained) (>= 13.1.0, <= 13.1.5); Any version (unconstrained) (>= 14.1.0, <= 14.1.5); Any version (unconstrained) (>= 15.1.0, <= 15.1.10); Any version (unconstrained) (>= 16.1.0, <= 16.1.4); Any version (unconstrained) (>= 17.1.0, <= 17.1.1)Canonical identity product-000cb533806b78ef860fa6bff163646e9d5756ef6c2d4d7d222692c4cd4c943fLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    12 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 13.1.0; through including 13.1.5
    Match ID
    9167fec1-2c37-4946-9657-b4e69301fb24
  2. cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    12 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 14.1.0; through including 14.1.5
    Match ID
    7b4b3442-e0c0-48cd-87ad-060e15c9801e
  3. cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    12 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 16.1.0; through including 16.1.4
    Match ID
    20662bb0-4c3d-4cf0-b068-3555c65dd06c
  4. cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    12 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 15.1.0; through including 15.1.10
    Match ID
    8fa85ec1-d91a-49dd-949b-2af7ac813ca5
  5. cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    12 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 17.1.0; through including 17.1.1
    Match ID
    d64edcad-f658-41a9-8838-41a2913ee8b7
NVD CPE · APPLICATIONf5big-ip_application_acceleration_managerVulnerable target · 5 assertions
Any version (unconstrained) (>= 13.1.0, <= 13.1.5); Any version (unconstrained) (>= 14.1.0, <= 14.1.5); Any version (unconstrained) (>= 15.1.0, <= 15.1.10); Any version (unconstrained) (>= 16.1.0, <= 16.1.4); Any version (unconstrained) (>= 17.1.0, <= 17.1.1)Canonical identity product-bcf09b1e7f256f8ae475f16dc9eb0c89893ad01b1d9c94b66d17ac875578a078Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    13 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 17.1.0; through including 17.1.1
    Match ID
    33b4fe55-81a7-41f8-adb8-b0f84c8205c4
  2. cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    13 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 14.1.0; through including 14.1.5
    Match ID
    9b88f9d1-b54b-40c7-a18a-26c4a071d7ec
  3. cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    13 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 15.1.0; through including 15.1.10
    Match ID
    c8f39403-c259-4d6f-9e9a-53671017eedb
  4. cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    13 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 13.1.0; through including 13.1.5
    Match ID
    7ec2324d-ec8b-41df-88a7-819e53aad0fc
  5. cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    13 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 16.1.0; through including 16.1.4
    Match ID
    220f2d38-fa82-45ef-b957-7678c9fedbc1
NVD CPE · APPLICATIONf5big-ip_application_security_managerVulnerable target · 5 assertions
Any version (unconstrained) (>= 13.1.0, <= 13.1.5); Any version (unconstrained) (>= 14.1.0, <= 14.1.5); Any version (unconstrained) (>= 15.1.0, <= 15.1.10); Any version (unconstrained) (>= 16.1.0, <= 16.1.4); Any version (unconstrained) (>= 17.1.0, <= 17.1.1)Canonical identity product-ba5b29ee89c2340743c5ed2999e757bf44af0086b8b527afdbbe3f8a626803daLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    11 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 14.1.0; through including 14.1.5
    Match ID
    f938eb43-8373-47eb-b269-c6df058a9244
  2. cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    11 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 16.1.0; through including 16.1.4
    Match ID
    5e86f3d5-65a4-48ce-a6a2-736bbb88e3f8
  3. cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    11 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 13.1.0; through including 13.1.5
    Match ID
    922aa845-530a-4b4b-9976-4cbc30c8a324
  4. cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    11 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 15.1.0; through including 15.1.10
    Match ID
    1771493e-acaa-477f-8ab4-25db12f6ad6e
  5. cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    11 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 17.1.0; through including 17.1.1
    Match ID
    31c4d96a-6d71-44b5-8b94-ae9dfa93873b
NVD CPE · APPLICATIONf5big-ip_application_visibility_and_reportingVulnerable target · 5 assertions
Any version (unconstrained) (>= 13.1.0, <= 13.1.5); Any version (unconstrained) (>= 14.1.0, <= 14.1.5); Any version (unconstrained) (>= 15.1.0, <= 15.1.10); Any version (unconstrained) (>= 16.1.0, <= 16.1.4); Any version (unconstrained) (>= 17.1.0, <= 17.1.1)Canonical identity product-e7831dd1502c92cf4956b2496298fff48f6f919ba0502487bde1ee5ad5c98016Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_application_visibility_and_reporting:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    14 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 17.1.0; through including 17.1.1
    Match ID
    8c61e3e7-c594-40d9-936a-19cd26b170e6
  2. cpe:2.3:a:f5:big-ip_application_visibility_and_reporting:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    14 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 15.1.0; through including 15.1.10
    Match ID
    4b9b76a1-7c5a-453f-a4ed-f1a81bcebeb5
  3. cpe:2.3:a:f5:big-ip_application_visibility_and_reporting:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    14 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 13.1.0; through including 13.1.5
    Match ID
    c7e422f6-c4c2-43ac-b137-0997b5739030
  4. cpe:2.3:a:f5:big-ip_application_visibility_and_reporting:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    14 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 14.1.0; through including 14.1.5
    Match ID
    cc3f710f-dbcb-4976-9719-cf063da22377
  5. cpe:2.3:a:f5:big-ip_application_visibility_and_reporting:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    14 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 16.1.0; through including 16.1.4
    Match ID
    88edfcd9-775c-48fa-9cda-2b04da8d0612
NVD CPE · APPLICATIONf5big-ip_automation_toolchainVulnerable target · 5 assertions
Any version (unconstrained) (>= 13.1.0, <= 13.1.5); Any version (unconstrained) (>= 14.1.0, <= 14.1.5); Any version (unconstrained) (>= 15.1.0, <= 15.1.10); Any version (unconstrained) (>= 16.1.0, <= 16.1.4); Any version (unconstrained) (>= 17.1.0, <= 17.1.1)Canonical identity product-b499054f70813299757594ac36607b49f4bcc0b7683d3f39d7ade03e99013f19Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_automation_toolchain:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 17.1.0; through including 17.1.1
    Match ID
    e874dd74-e654-44ee-a1a3-57d7ca772fb1
  2. cpe:2.3:a:f5:big-ip_automation_toolchain:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 15.1.0; through including 15.1.10
    Match ID
    56800e2e-119d-468b-b407-9cfacd8c00d7
  3. cpe:2.3:a:f5:big-ip_automation_toolchain:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 16.1.0; through including 16.1.4
    Match ID
    caa278ba-b020-4bed-91da-1cd8966512d6
  4. cpe:2.3:a:f5:big-ip_automation_toolchain:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 14.1.0; through including 14.1.5
    Match ID
    3d33aa82-3ae5-4165-9b54-8c03381d98ad
  5. cpe:2.3:a:f5:big-ip_automation_toolchain:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 13.1.0; through including 13.1.5
    Match ID
    89ada880-7a5b-49da-aea4-bc19d7c41916
NVD CPE · APPLICATIONf5big-ip_carrier-grade_natVulnerable target · 5 assertions
Any version (unconstrained) (>= 13.1.0, <= 13.1.5); Any version (unconstrained) (>= 14.1.0, <= 14.1.5); Any version (unconstrained) (>= 15.1.0, <= 15.1.10); Any version (unconstrained) (>= 16.1.0, <= 16.1.4); Any version (unconstrained) (>= 17.1.0, <= 17.1.1)Canonical identity product-b655dc8d5b821afddbd8d93fa9489ee15a0d676811bd45d3730fe3b26cdd735dLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_carrier-grade_nat:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 13.1.0; through including 13.1.5
    Match ID
    4c9fcbcb-9ce0-49e7-85c8-69e71d211912
  2. cpe:2.3:a:f5:big-ip_carrier-grade_nat:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 16.1.0; through including 16.1.4
    Match ID
    21d51d9f-2840-4dea-a007-d20111a1745c
  3. cpe:2.3:a:f5:big-ip_carrier-grade_nat:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 14.1.0; through including 14.1.5
    Match ID
    112dfa85-90ad-478d-bd70-8c7c0c074f1b
  4. cpe:2.3:a:f5:big-ip_carrier-grade_nat:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 17.1.0; through including 17.1.1
    Match ID
    c640fa3f-7ab7-4875-b01d-9db41ceb432b
  5. cpe:2.3:a:f5:big-ip_carrier-grade_nat:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 15.1.0; through including 15.1.10
    Match ID
    db704a1c-d8b7-48bb-a15a-c14db591fe4a
NVD CPE · APPLICATIONf5big-ip_container_ingress_servicesVulnerable target · 5 assertions
Any version (unconstrained) (>= 13.1.0, <= 13.1.5); Any version (unconstrained) (>= 14.1.0, <= 14.1.5); Any version (unconstrained) (>= 15.1.0, <= 15.1.10); Any version (unconstrained) (>= 16.1.0, <= 16.1.4); Any version (unconstrained) (>= 17.1.0, <= 17.1.1)Canonical identity product-5baa90dcb54b8e683bcfbe334e0b18cbe8ea2d032eb45cd55f7afcfa9da03368Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_container_ingress_services:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    8 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 16.1.0; through including 16.1.4
    Match ID
    3095b6f6-c2ff-44b2-97aa-eef5f475a608
  2. cpe:2.3:a:f5:big-ip_container_ingress_services:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    8 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 14.1.0; through including 14.1.5
    Match ID
    5630f852-7110-4332-95df-2d34365ba076
  3. cpe:2.3:a:f5:big-ip_container_ingress_services:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    8 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 13.1.0; through including 13.1.5
    Match ID
    5d87ee02-c9af-4824-bab1-5f674c51d78e
  4. cpe:2.3:a:f5:big-ip_container_ingress_services:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    8 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 17.1.0; through including 17.1.1
    Match ID
    437ca326-41b9-4dbd-93b6-1ff93f5eafce
  5. cpe:2.3:a:f5:big-ip_container_ingress_services:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    8 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 15.1.0; through including 15.1.10
    Match ID
    425a5d8f-c719-459f-8ff4-fc3efb4b6bb3
NVD CPE · APPLICATIONf5big-ip_ddos_hybrid_defenderVulnerable target · 5 assertions
Any version (unconstrained) (>= 13.1.0, <= 13.1.5); Any version (unconstrained) (>= 14.1.0, <= 14.1.5); Any version (unconstrained) (>= 15.1.0, <= 15.1.10); Any version (unconstrained) (>= 16.1.0, <= 16.1.4); Any version (unconstrained) (>= 17.1.0, <= 17.1.1)Canonical identity product-f87c7b9b64c86afcc0c48220bda1bc92543beefff7155621fe458a2627cfe653Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 17.1.0; through including 17.1.1
    Match ID
    7479843e-f2d9-4815-95bc-f4223119753c
  2. cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 15.1.0; through including 15.1.10
    Match ID
    8070b469-8cc4-4d2f-97d7-12d0abb963c1
  3. cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 16.1.0; through including 16.1.4
    Match ID
    a326597e-725d-45de-bef7-2ed92137b253
  4. cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 14.1.0; through including 14.1.5
    Match ID
    2fbce2d1-9d93-415d-ab2c-2060307c305a
  5. cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 13.1.0; through including 13.1.5
    Match ID
    caef3ea4-7d5a-4b44-9ce3-258aec745866
NVD CPE · APPLICATIONf5big-ip_domain_name_systemVulnerable target · 5 assertions
Any version (unconstrained) (>= 13.1.0, <= 13.1.5); Any version (unconstrained) (>= 14.1.0, <= 14.1.5); Any version (unconstrained) (>= 15.1.0, <= 15.1.10); Any version (unconstrained) (>= 16.1.0, <= 16.1.4); Any version (unconstrained) (>= 17.1.0, <= 17.1.1)Canonical identity product-8f453bafc34e9c461b1290b73550569e7558e64398eede2e74d46d6cb72adae8Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    10 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 16.1.0; through including 16.1.4
    Match ID
    c966faba-7199-4f0d-ab8c-4590fe9d2fff
  2. cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    10 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 15.1.0; through including 15.1.10
    Match ID
    98d2ce1e-ded0-470a-aa78-c78ef769c38e
  3. cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    10 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 17.1.0; through including 17.1.1
    Match ID
    375d359b-e05b-4aec-9b39-46911847a410
  4. cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    10 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 13.1.0; through including 13.1.5
    Match ID
    08b25aab-a98c-4f89-9131-29e3a8c0ed23
  5. cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    10 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 14.1.0; through including 14.1.5
    Match ID
    ed9b976a-d3ad-4445-bf8a-067c3ebdfbb0
NVD CPE · APPLICATIONf5big-ip_fraud_protection_servicesVulnerable target · 5 assertions
Any version (unconstrained) (>= 13.1.0, <= 13.1.5); Any version (unconstrained) (>= 14.1.0, <= 14.1.5); Any version (unconstrained) (>= 15.1.0, <= 15.1.10); Any version (unconstrained) (>= 16.1.0, <= 16.1.4); Any version (unconstrained) (>= 17.1.0, <= 17.1.1)Canonical identity product-ec18136a1fd9c7ae5d975d2a2f5c0037e57c749e49c0715b9b8a25d6f0ee853dLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_fraud_protection_services:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    15 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 14.1.0; through including 14.1.5
    Match ID
    00deabfc-139a-4306-bcfa-6ce700d64327
  2. cpe:2.3:a:f5:big-ip_fraud_protection_services:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    15 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 17.1.0; through including 17.1.1
    Match ID
    b84c35ad-d355-4db4-99f1-6eba2d91f322
  3. cpe:2.3:a:f5:big-ip_fraud_protection_services:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    15 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 15.1.0; through including 15.1.10
    Match ID
    958c34e5-668d-416a-99af-2c6f042a2215
  4. cpe:2.3:a:f5:big-ip_fraud_protection_services:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    15 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 16.1.0; through including 16.1.4
    Match ID
    659376e8-fcca-45e1-bdfb-c50117a66484
  5. cpe:2.3:a:f5:big-ip_fraud_protection_services:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    15 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 13.1.0; through including 13.1.5
    Match ID
    84d9cd72-ed25-4447-9dd5-41ed51c891e5
NVD CPE · APPLICATIONf5big-ip_global_traffic_managerVulnerable target · 5 assertions
Any version (unconstrained) (>= 13.1.0, <= 13.1.5); Any version (unconstrained) (>= 14.1.0, <= 14.1.5); Any version (unconstrained) (>= 15.1.0, <= 15.1.10); Any version (unconstrained) (>= 16.1.0, <= 16.1.4); Any version (unconstrained) (>= 17.1.0, <= 17.1.1)Canonical identity product-618e73be1c78cebd98c0451389a4bfe0fed7033b9a99c5dfef4ab081a1711fd0Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    16 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 15.1.0; through including 15.1.10
    Match ID
    5d2a121f-5bd2-4263-8ed3-1dde25b5c306
  2. cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    16 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 17.1.0; through including 17.1.1
    Match ID
    df43cd3a-2c94-4663-b5d5-0327fd3e1f3d
  3. cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    16 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 16.1.0; through including 16.1.4
    Match ID
    0a4f7bad-3edd-4de0-aab7-de5aca34dd79
  4. cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    16 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 13.1.0; through including 13.1.5
    Match ID
    e6018b01-048c-43bb-a78d-66910ed60ca9
  5. cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    16 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 14.1.0; through including 14.1.5
    Match ID
    3a6a5686-5a8b-45d5-9165-bc99d2ccac47
NVD CPE · APPLICATIONf5big-ip_link_controllerVulnerable target · 5 assertions
Any version (unconstrained) (>= 13.1.0, <= 13.1.5); Any version (unconstrained) (>= 14.1.0, <= 14.1.5); Any version (unconstrained) (>= 15.1.0, <= 15.1.10); Any version (unconstrained) (>= 16.1.0, <= 16.1.4); Any version (unconstrained) (>= 17.1.0, <= 17.1.1)Canonical identity product-8754268b8c2cde0fe6aca92689e07534654bf0c32f504fdc7eabdc3dd51c0dabLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    17 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 17.1.0; through including 17.1.1
    Match ID
    95c1f4f7-7533-44ce-be4c-bf71eafa62ea
  2. cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    17 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 15.1.0; through including 15.1.10
    Match ID
    29563719-1af2-4bb8-8cca-a0869f87795d
  3. cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    17 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 16.1.0; through including 16.1.4
    Match ID
    d24815dd-579a-46d1-b9f2-3bb2c56bc54d
  4. cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    17 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 14.1.0; through including 14.1.5
    Match ID
    f70d4b6f-65cf-48f4-9a07-072dfbce53d9
  5. cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    17 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 13.1.0; through including 13.1.5
    Match ID
    d9ec2237-117f-43bd-adec-516cf72e04ef
NVD CPE · APPLICATIONf5big-ip_local_traffic_managerVulnerable target · 5 assertions
Any version (unconstrained) (>= 13.1.0, <= 13.1.5); Any version (unconstrained) (>= 14.1.0, <= 14.1.5); Any version (unconstrained) (>= 15.1.0, <= 15.1.10); Any version (unconstrained) (>= 16.1.0, <= 16.1.4); Any version (unconstrained) (>= 17.1.0, <= 17.1.1)Canonical identity product-dfc8c075c3b90f711dd6c07c1d70e2c3507742bbcffef3651f2737a4133eeb81Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 14.1.0; through including 14.1.5
    Match ID
    7a4607bf-41ac-4e84-a110-74e085ff0445
  2. cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 13.1.0; through including 13.1.5
    Match ID
    0360f76d-e75e-4b05-a294-b47012323ed9
  3. cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 16.1.0; through including 16.1.4
    Match ID
    46ba8e8a-6ed5-4fb2-8bbc-586aa031085a
  4. cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 17.1.0; through including 17.1.1
    Match ID
    820076a8-f163-4471-8b1e-5290bd1d6d93
  5. cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 15.1.0; through including 15.1.10
    Match ID
    441cc945-7ca3-49c0-ae10-94725301e31d
NVD CPE · APPLICATIONf5big-ip_policy_enforcement_managerVulnerable target · 5 assertions
Any version (unconstrained) (>= 13.1.0, <= 13.1.5); Any version (unconstrained) (>= 14.1.0, <= 14.1.5); Any version (unconstrained) (>= 15.1.0, <= 15.1.10); Any version (unconstrained) (>= 16.1.0, <= 16.1.4); Any version (unconstrained) (>= 17.1.0, <= 17.1.1)Canonical identity product-b94ca11deae6f3dbdfe71c801d37911c9fd185c5bd3c37c804c67d15918d47d3Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 15.1.0; through including 15.1.10
    Match ID
    fff5007e-761c-4697-8d34-c064df0abe8d
  2. cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 16.1.0; through including 16.1.4
    Match ID
    910441d3-90ef-4375-b007-d51120a60ab2
  3. cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 13.1.0; through including 13.1.5
    Match ID
    8257aa59-c14d-4ec1-b22c-dfbb92cbc297
  4. cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 17.1.0; through including 17.1.1
    Match ID
    17523f89-df78-45b7-aeab-a4886e99e08b
  5. cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 14.1.0; through including 14.1.5
    Match ID
    37db32bb-f4ba-4fb5-94b1-55c3f06749cf
NVD CPE · APPLICATIONf5big-ip_ssl_orchestratorVulnerable target · 5 assertions
Any version (unconstrained) (>= 13.1.0, <= 13.1.5); Any version (unconstrained) (>= 14.1.0, <= 14.1.5); Any version (unconstrained) (>= 15.1.0, <= 15.1.10); Any version (unconstrained) (>= 16.1.0, <= 16.1.4); Any version (unconstrained) (>= 17.1.0, <= 17.1.1)Canonical identity product-1f7d291882e58db33699a4631d94b94ac47c4054e89f4ab9ba55e10df6020b64Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_ssl_orchestrator:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 13.1.0; through including 13.1.5
    Match ID
    8a6f9699-a485-4614-8f38-5a556d31617e
  2. cpe:2.3:a:f5:big-ip_ssl_orchestrator:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 17.1.0; through including 17.1.1
    Match ID
    25e7dbe6-d708-4257-ba8b-90a4db6de1ea
  3. cpe:2.3:a:f5:big-ip_ssl_orchestrator:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 15.1.0; through including 15.1.10
    Match ID
    e76e1b82-f1dc-4366-b388-dbdf16c586a0
  4. cpe:2.3:a:f5:big-ip_ssl_orchestrator:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 14.1.0; through including 14.1.5
    Match ID
    5a90f547-97a2-41ec-9fdf-25f869f0fa38
  5. cpe:2.3:a:f5:big-ip_ssl_orchestrator:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 16.1.0; through including 16.1.4
    Match ID
    660137f4-15a1-42d1-bbac-99a1d5bb398b
NVD CPE · APPLICATIONf5big-ip_webacceleratorVulnerable target · 5 assertions
Any version (unconstrained) (>= 13.1.0, <= 13.1.5); Any version (unconstrained) (>= 14.1.0, <= 14.1.5); Any version (unconstrained) (>= 15.1.0, <= 15.1.10); Any version (unconstrained) (>= 16.1.0, <= 16.1.4); Any version (unconstrained) (>= 17.1.0, <= 17.1.1)Canonical identity product-9a98c46bb3d6ba9611bd32eab93edabd599af91bf31121c045dc220d5c65e47bLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    18 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 14.1.0; through including 14.1.5
    Match ID
    d47b7691-a95b-45c0-bab4-27e047f3c379
  2. cpe:2.3:a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    18 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 16.1.0; through including 16.1.4
    Match ID
    3a599f90-f66b-4df0-ad7d-d234f328bd59
  3. cpe:2.3:a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    18 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 17.1.0; through including 17.1.1
    Match ID
    609593ad-6e6d-4b8d-b01b-ef4768e8df10
  4. cpe:2.3:a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    18 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 15.1.0; through including 15.1.10
    Match ID
    2cd1637d-0e42-4928-867a-ba0fdb6e8462
  5. cpe:2.3:a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    18 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 13.1.0; through including 13.1.5
    Match ID
    1932d32d-0e4b-4bbd-816f-6d47ab2e2f04
NVD CPE · APPLICATIONf5big-ip_websafeVulnerable target · 5 assertions
Any version (unconstrained) (>= 13.1.0, <= 13.1.5); Any version (unconstrained) (>= 14.1.0, <= 14.1.5); Any version (unconstrained) (>= 15.1.0, <= 15.1.10); Any version (unconstrained) (>= 16.1.0, <= 16.1.4); Any version (unconstrained) (>= 17.1.0, <= 17.1.1)Canonical identity product-59c1a99b28f4b9b4655fbcd860d02e1150ce2f13239c2e93385600c2666878baLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_websafe:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    19 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 15.1.0; through including 15.1.10
    Match ID
    eccb8c30-861e-4e48-a5f5-30ee523c1fb6
  2. cpe:2.3:a:f5:big-ip_websafe:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    19 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 13.1.0; through including 13.1.5
    Match ID
    5326759a-afb0-4a15-b4e9-3c9a2e5db32a
  3. cpe:2.3:a:f5:big-ip_websafe:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    19 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 14.1.0; through including 14.1.5
    Match ID
    57d92d05-c67d-437e-88f3-dcc3f6b0ed2f
  4. cpe:2.3:a:f5:big-ip_websafe:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    19 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 16.1.0; through including 16.1.4
    Match ID
    f5fead2a-3a58-432e-bebb-6e3fde24395f
  5. cpe:2.3:a:f5:big-ip_websafe:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    19 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 17.1.0; through including 17.1.1
    Match ID
    2044d97e-5637-45ba-a004-a717b5e793fd

Affected-product evidence

Accepted scope and product mapping

20 canonical links · 1 source-reported links

Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-000cb533806b78ef860fa6bff163646e9d5756ef6c2d4d7d222692c4cd4c943f

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
897e9783-7d53-43ab-94e2-e9e37b369fc09a8047a9-600f-47f8-9ecb-557a8e4875a29b77f67c-946b-41cf-a0a3-0ffc2974ef73d727bda9-191d-4eba-ae1a-d2dedfef93faf865b8f4-6d68-49bf-8911-e0e5ace298a6
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-1f7d291882e58db33699a4631d94b94ac47c4054e89f4ab9ba55e10df6020b64

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
0e09b5f5-0733-4e98-8e08-36dbc9579e280f1c6bb4-d9e4-4c3c-a046-cfeb1ddad2f880d9ea10-711c-4b6a-8c61-4b8aae8571c6d86e6d86-774a-4e0d-9684-2bbf235ad9a9e6216ef2-2dcf-428a-a1ab-8751a77071e1
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-3159127811fadcfbf55e58810b397c704a5ecb216e89a6fccc26cab6944674c7

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
35e404ae-8d52-49a9-a5f4-e35600fce654971e7b35-8b96-4cb9-9c74-6bd7537c66cea7ef4670-52a2-494e-90da-bd8f4ef42271c1939ce2-1e1f-457c-ba79-b4f12974194fe06cf31a-1813-461d-bc12-2538df3c0b3a
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-59c1a99b28f4b9b4655fbcd860d02e1150ce2f13239c2e93385600c2666878ba

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
350ea121-0787-4756-ab05-ea02680683668c4e5a2d-43c9-4e77-a3e3-35285982279a930081cb-7a01-45df-ab92-ce7507082815a43e0c8f-1677-4ac2-bd15-bd0f45a90abcb5209dbb-7422-492a-9d4a-f3663d9b40e2
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-5baa90dcb54b8e683bcfbe334e0b18cbe8ea2d032eb45cd55f7afcfa9da03368

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
16267cb2-3051-4c15-935c-134de1b3bab16526a288-9116-40c9-a3cf-2a7eb6c31bc573807b11-c102-4ab1-8df4-61d15783917fe2495609-ad70-46d7-bd31-e956f1168a71e34e3cb3-0149-443c-a6de-c1d36c814a48
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-618e73be1c78cebd98c0451389a4bfe0fed7033b9a99c5dfef4ab081a1711fd0

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
07bc428b-123e-4d84-b3f7-85448aff531f675cae59-8142-4d70-b438-ddf8fdd608d0b3416954-8208-46a4-b202-b0cc8371dd63e683515c-7eae-41ce-bdef-5977f22bed14ff7954aa-0301-4f13-bad1-b03b13b65f3e
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-8754268b8c2cde0fe6aca92689e07534654bf0c32f504fdc7eabdc3dd51c0dab

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
1c5b5874-4b73-46f7-8d19-f9db0e9094c08791e5e1-cc1a-49da-afc0-73761974c6fb90f66bae-5625-4676-961c-3257af3cd034b39eb45a-f85f-45b7-9a08-3661917cfdc4d7a1932d-9e03-4b9c-837f-7dec5856db9b
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-8f453bafc34e9c461b1290b73550569e7558e64398eede2e74d46d6cb72adae8

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
1bd45ed6-4592-42cc-ae18-72afcccf5220ae38e81a-0ee0-4380-a54f-8999bf547edadd82484b-106f-49a8-81c4-218684b36a97edffcbcd-92f3-46d8-b4fa-2055a391faa3fa91f889-a892-4e84-88af-ad1dbd54dece
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-9a98c46bb3d6ba9611bd32eab93edabd599af91bf31121c045dc220d5c65e47b

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
20847f96-b758-4c65-bafb-e61007d95845216bb3b8-8fef-4883-94aa-2cf28f53c05f224ba2e0-e9ba-4ac7-8f25-db2d9b4a26015fbe586d-ab8f-451f-8c72-ef0df92b9137beb44f49-cf99-43da-be61-b57aa76e9c34
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-b499054f70813299757594ac36607b49f4bcc0b7683d3f39d7ade03e99013f19

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
1433ab41-b94a-4721-9327-4c3d97ea93101b535157-eaa0-4617-8481-b3cdc44b0e91817957b0-e074-4e3d-994f-a0467a3b8272ae987c85-e1aa-4ba5-86a4-19416a878151da5be445-c12c-48f3-96cb-e9914ed7f31a
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-b655dc8d5b821afddbd8d93fa9489ee15a0d676811bd45d3730fe3b26cdd735d

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
0d87bdcd-89ca-46b5-9dc4-093599bc3dbe56703811-8ddb-4c22-bbf7-5a654642631181e7cd02-4703-460b-a7ee-1cb682045f1b875877dc-6caf-464b-ba80-1fbd70389cf9b7d4e12a-3c3c-416c-9b4a-cf8c81e8c35a
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-b94ca11deae6f3dbdfe71c801d37911c9fd185c5bd3c37c804c67d15918d47d3

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
1d3773fe-6e3f-4bbd-9046-6a677b459137759471af-a46c-4869-82e2-796be283dc74ae5a05a5-f9d8-476a-8b88-c666c2a55e2ebbb8ee17-21b1-4ab7-aaf2-4b371ffda6d6d3917cf6-2fd6-4582-bebf-6291214efb02
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-ba5b29ee89c2340743c5ed2999e757bf44af0086b8b527afdbbe3f8a626803da

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
1a9884a3-1b1e-4840-8d3f-369e5eff00bc3007de18-2403-4eec-be92-1e3b040e65f94867eb88-2424-43a4-b329-5901a5499018502a446f-7a6f-4653-b171-08a78f80f4617758a86c-f8bc-4c06-ab18-98890bcf5a25
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-bcf09b1e7f256f8ae475f16dc9eb0c89893ad01b1d9c94b66d17ac875578a078

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
07ca9e12-ecbc-4040-bbe2-44772323c5292be454ce-0198-45fe-bd3e-6e4227bfe27255a27ce2-c862-44df-8841-13c4ffcf9da8a5025806-1765-4d75-9ca4-b484373d0b46e1d42504-42f0-4237-bc04-d0d93af41a79
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-c611bfdeac48cac2141d0aebba0e7ba6ff1c599d72cfe95a76f1db1b7fe68b36

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
0cb56db5-53b5-4e56-a34c-9fc6f6a3ebb319eb2e70-a703-47d1-8ff7-ae89200eed6935a064b1-b36a-4fb3-93cb-472194739ebd66c7b5b1-5433-462a-93de-c206a3d4e074aaad4106-2127-4b50-9403-923695dbbb5e
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-dfc8c075c3b90f711dd6c07c1d70e2c3507742bbcffef3651f2737a4133eeb81

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
1a52a70d-f2a1-4305-a1d6-7a606f833596404331d7-419d-48c3-987e-459e1f54074a56e3f8f7-b7cb-4d3b-aa0d-fe5062f3fe38624b02f9-a550-45c5-b412-5ef155af06c977f0fd73-9e70-47c5-a578-f95a9b96fc18
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-e7831dd1502c92cf4956b2496298fff48f6f919ba0502487bde1ee5ad5c98016

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
33bf1f3c-a35b-4d9a-9dc1-725307b18fd08c3bffad-f461-4f7a-9eaf-be65f5e9a90be6523d85-b51c-4596-8801-74c1683e6f7feb756bee-e46d-4efd-9a7d-fb750056ec79f0195d50-3b51-4d62-8468-52a2835564bf
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-ec18136a1fd9c7ae5d975d2a2f5c0037e57c749e49c0715b9b8a25d6f0ee853d

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
22e0ad02-9ee9-4c05-8a26-1d073141177a2657d2bc-601a-4e2c-8d3e-5d92e876fb6c534d87d5-5f2d-487b-9a92-c833442257866008e05b-6302-4c1c-a1c5-2ce3303b725d944eecbc-4de8-41f8-b573-7c4c56498fc5
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-f87c7b9b64c86afcc0c48220bda1bc92543beefff7155621fe458a2627cfe653

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
23822634-38c1-49e8-a5f7-3dd471af254b6c71f97a-c96b-43b0-a225-47743a30ab22781a72d1-dfbe-454c-b725-254bad145d737b6f8dfc-05c7-4fa5-a657-481f9198bfb4ceb59e32-ee47-495f-b045-fd436d09ee2c
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-fe8f45eed4bb3ac6e69f6f6fbf87e9e25862951e870386e176dca756ebfdb2cb

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
05b1074b-6038-4e89-81bb-d4d1feadd84429f566ab-234b-494c-af68-6b9ea411a6b35638c9da-1351-40af-aa50-10fa277df7df5ded46e6-d8e0-4f8c-9541-3cc36231c19e86e48fcb-8459-4820-8912-971aa6ef04b5
Source-reported scopeSource-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Vendor specified only by source · Product specified only by source

Source class
Direct cve affected
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
870364a6-f772-4c5f-9a50-398fca67f9c0

Assessments

CVSS by origin

8.8
NVDCVSS 3.1 · role Primary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
8.8
f5sirt@f5.comCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
8.8
f5CVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Direct CVE/CNA normalized decisions

8.8Priority eligible

f5

CVSS 3.1 · Primary · Original assertion · rank 1

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Validation
Valid match
Recomputed
8.8
Decision reason
Evidence supported
Policy
casca-direct-cvss-eligibility-v1

Assessments are retained side by side under closed precedence. Cascade never averages CVSS.

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.