CVE-2026-63020
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
Summary
A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages
Impact:
An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a spoofed error message in the victim's BIG-IP Configuration utility web browser session. This is a control plane issue; there is no data plane exposure.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| F5 | BIG-IP | 21.1.0 < 21.1.0.1 | affected |
| F5 | BIG-IP | 21.0.0 < 21.0.0.3 | affected |
| F5 | BIG-IP | 17.5.0 < 17.5.1.8 | affected |
| F5 | BIG-IP | 17.1.0 < 17.1.3.4 | affected |
Weaknesses
- CWE-451: CWE-451: User Interface (UI) Misrepresentation of Critical Information
Workarounds
To mitigate this vulnerability, you may take the following actions:
When you have finished using the BIG-IP Configuration utility, you should log off and close all instances of your web browser. Do not use the same web browser that you use to manage the BIG-IP Configuration utility for any other purposes, such as browsing the internet. If you must perform both actions on the same client machine, F5 recommends that you do so in separate browsers
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.