Description
A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages 





Impact:


An attacker may trick authenticated BIG-IP users
into accessing malicious links and reflect a spoofed error message in
the victim's BIG-IP Configuration utility web browser session. This is a
control plane issue; there is no data plane exposure.





Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published: 2026-09-02
Score: 2.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides in an undisclosed page of the BIG‑IP Configuration utility. During normal operation, authenticated users can trigger the page and see error messages generated by the application. The vulnerability allows an attacker to cause the system to return a fabricated error message and include a link. Leveraged by an attacker, the forged message can lure the user to a malicious site, potentially compromising the attacker’s control plane or preparing for future attacks. Because the issue only affects the configuration interface, it does not expose the data‑plane or compromise configuration data directly.

Affected Systems

Affected systems are F5 BIG‑IP appliances running the Configuration utility. No specific firmware or software versions are listed in the advisory, and products that have reached End of Technical Support are not evaluated.

Risk and Exploitability

The overall risk is moderate low, reflected by a CVSS score of 2.3 and the absence of a KEV listing. The vulnerability requires an attacker to first have a valid authenticated session in the BIG‑IP Configuration utility and then persuade the victim to click a link displayed in a spoofed error message. Because it is a control‑plane flaw with no impact on the data plane and no publicly available exploits are known, the probability of exploitation is low. However, the potential for social‑engineering attacks remains, so administrators should still apply the recommended mitigation.

Generated by OpenCVE AI on September 3, 2026 at 09:29 UTC.

Remediation

Vendor Workaround

To mitigate this vulnerability, you may take the following actions: When you have finished using the BIG-IP Configuration utility, you should log off and close all instances of your web browser. Do not use the same web browser that you use to manage the BIG-IP Configuration utility for any other purposes, such as browsing the internet. If you must perform both actions on the same client machine, F5 recommends that you do so in separate browsers


OpenCVE Recommended Actions

  • Log out of the BIG‑IP Configuration utility and close all browser tabs after use.
  • Avoid using the same browser for external browsing; use a separate browser for internet use.
  • When both tasks must be performed on the same client machine, use distinct browsers or separate machines.

Generated by OpenCVE AI on September 3, 2026 at 09:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared F5
F5 big-ip
Vendors & Products F5
F5 big-ip

Wed, 02 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages  Impact: An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a spoofed error message in the victim's BIG-IP Configuration utility web browser session. This is a control plane issue; there is no data plane exposure. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Title BIG-IP Configuration utility vulnerability
Weaknesses CWE-451
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: f5

Published:

Updated: 2026-09-02T17:55:45.119Z

Reserved: 2026-07-24T22:40:21.245Z

Link: CVE-2026-63020

cve-icon Vulnrichment

Updated: 2026-09-02T17:55:40.635Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-02T16:17:18.400

Modified: 2026-09-02T19:23:13.660

Link: CVE-2026-63020

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T10:15:04Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information