Impact
The flaw resides in an undisclosed page of the BIG‑IP Configuration utility. During normal operation, authenticated users can trigger the page and see error messages generated by the application. The vulnerability allows an attacker to cause the system to return a fabricated error message and include a link. Leveraged by an attacker, the forged message can lure the user to a malicious site, potentially compromising the attacker’s control plane or preparing for future attacks. Because the issue only affects the configuration interface, it does not expose the data‑plane or compromise configuration data directly.
Affected Systems
Affected systems are F5 BIG‑IP appliances running the Configuration utility. No specific firmware or software versions are listed in the advisory, and products that have reached End of Technical Support are not evaluated.
Risk and Exploitability
The overall risk is moderate low, reflected by a CVSS score of 2.3 and the absence of a KEV listing. The vulnerability requires an attacker to first have a valid authenticated session in the BIG‑IP Configuration utility and then persuade the victim to click a link displayed in a spoofed error message. Because it is a control‑plane flaw with no impact on the data plane and no publicly available exploits are known, the probability of exploitation is low. However, the potential for social‑engineering attacks remains, so administrators should still apply the recommended mitigation.
OpenCVE Enrichment