CVE-2026-20732 PUBLISHED CVSS 3.0999999046325684 LOW

A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

EPSS 0.05% · 17.3th percentile

Risk Scores

CVSS v3.1
3.0999999046325684
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
EPSS Score
0.05%
17.3th percentile

Affected Products

VendorProductVersions
f5big-ip_ssl_orchestrator17.5.0, 16.1.0, 17.5.0
f5big-ip_local_traffic_manager16.1.0, 17.5.0, 16.1.0
f5big-ip_application_security_manager17.1.0, 16.1.0, 17.5.0
f5big-ip_advanced_firewall_manager17.1.0, 17.5.0, 16.1.0
f5big-ip_webaccelerator17.1.0, 17.1.0, 17.5.0
f5big-ip_application_acceleration_manager17.5.0, 16.1.0, 17.1.0
f5big-ip_advanced_web_application_firewall17.5.0, 16.1.0, 17.5.0
f5big-ip_fraud_protection_service16.1.0, 17.5.0, 16.1.0
f5big-ip_container_ingress_services17.1.0, 16.1.0, 17.5.0
f5big-ip_global_traffic_manager17.1.0, 17.5.0, 16.1.0
f5big-ip_websafe16.1.0, 16.1.0, 17.1.0
F5BIG-IP16.1.0, 17.5.0, 17.5.0
f5big-ip_application_visibility_and_reporting17.1.0, 16.1.0, 17.5.0
f5big-ip_analytics17.1.0, 17.5.0, 16.1.0
f5big-ip_automation_toolchain16.1.0, 17.1.0, 17.5.0
f5big-ip_access_policy_manager17.5.0, 16.1.0, 17.1.0
f5big-ip_ddos_hybrid_defender17.5.0, 17.5.0, 17.1.0
f5big-ip_policy_enforcement_manager17.5.0, 16.1.0, 17.1.0
f5big-ip_carrier-grade_nat17.5.0, 17.1.0, 17.5.0
f5big-ip_link_controller16.1.0, 17.1.0, 17.5.0.

…and 2 more

Timeline

References

Open in Interactive Console →