CVE-2026-63020 (GCVE-0-2026-63020)
Vulnerability from cvelistv5
Published
2026-09-02 15:40
Modified
2026-09-02 17:55
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-451 - User Interface (UI) Misrepresentation of Critical Information
Summary
A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages
Impact:
An attacker may trick authenticated BIG-IP users
into accessing malicious links and reflect a spoofed error message in
the victim's BIG-IP Configuration utility web browser session. This is a
control plane issue; there is no data plane exposure.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
References
| URL | Tags | ||||
|---|---|---|---|---|---|
|
|||||
Impacted products
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-63020",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-02T17:55:36.352848Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-02T17:55:45.119Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unknown",
"modules": [
"All Modules"
],
"product": "BIG-IP",
"vendor": "F5",
"versions": [
{
"lessThan": "21.1.0.1",
"status": "affected",
"version": "21.1.0",
"versionType": "custom"
},
{
"lessThan": "21.0.0.3",
"status": "affected",
"version": "21.0.0",
"versionType": "custom"
},
{
"lessThan": "17.5.1.8",
"status": "affected",
"version": "17.5.0",
"versionType": "custom"
},
{
"lessThan": "17.1.3.4",
"status": "affected",
"version": "17.1.0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "F5 acknowledges Micha\u0142 Majchrowicz, Marcin Wyczechowski and Piotr Zdunek (members of the AFINE Team) for bringing this issue to our attention and following the highest standards of coordinated disclosure."
}
],
"datePublic": "2026-08-19T04:00:00.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cdiv\u003eA vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages\u0026nbsp;\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003e\n\u003cp\u003eImpact:\u003c/p\u003e\n\u003cp\u003eAn attacker may trick authenticated BIG-IP users \ninto accessing malicious links and reflect a spoofed error message in \nthe victim\u0027s BIG-IP Configuration utility web browser session. This is a\n control plane issue; there is no data plane exposure.\u003c/p\u003e\n\n\u003c/div\u003e\u003cdiv\u003eNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.\u003c/div\u003e"
}
],
"value": "A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages\u00a0\n\n\n\n\n\nImpact:\n\n\nAn attacker may trick authenticated BIG-IP users \ninto accessing malicious links and reflect a spoofed error message in \nthe victim\u0027s BIG-IP Configuration utility web browser session. This is a\n control plane issue; there is no data plane exposure.\n\n\n\n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 3.1,
"baseSeverity": "LOW",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "HIGH",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 2.3,
"baseSeverity": "LOW",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "PASSIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "LOW",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-451",
"description": "CWE-451: User Interface (UI) Misrepresentation of Critical Information",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-02T15:40:53.437Z",
"orgId": "9dacffd4-cb11-413f-8451-fbbfd4ddc0ab",
"shortName": "f5"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://my.f5.com/manage/s/article/K000161728"
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "BIG-IP Configuration utility vulnerability",
"workarounds": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eTo mitigate this vulnerability, you may take the following actions:\u003c/p\u003e\n\u003cp\u003eWhen you have finished using the BIG-IP \nConfiguration utility, you should log off and close all instances of \nyour web browser. Do not use the same web browser that you use to manage\n the BIG-IP Configuration utility for any other purposes, such as \nbrowsing the internet. If you must perform both actions on the same \nclient machine, F5 recommends that you do so in separate browsers\u003c/p\u003e"
}
],
"value": "To mitigate this vulnerability, you may take the following actions:\n\n\nWhen you have finished using the BIG-IP \nConfiguration utility, you should log off and close all instances of \nyour web browser. Do not use the same web browser that you use to manage\n the BIG-IP Configuration utility for any other purposes, such as \nbrowsing the internet. If you must perform both actions on the same \nclient machine, F5 recommends that you do so in separate browsers"
}
],
"x_generator": {
"engine": "F5 SIRTBot v1.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "9dacffd4-cb11-413f-8451-fbbfd4ddc0ab",
"assignerShortName": "f5",
"cveId": "CVE-2026-63020",
"datePublished": "2026-09-02T15:40:53.437Z",
"dateReserved": "2026-07-24T22:40:21.245Z",
"dateUpdated": "2026-09-02T17:55:45.119Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"vulnerability-lookup:meta": {
"vulnrichment": {
"containers": "{\"adp\": [{\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2026-63020\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2026-09-02T17:55:36.352848Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2026-09-02T17:55:40.635Z\"}}], \"cna\": {\"title\": \"BIG-IP Configuration utility vulnerability\", \"source\": {\"discovery\": \"EXTERNAL\"}, \"credits\": [{\"lang\": \"en\", \"type\": \"finder\", \"value\": \"F5 acknowledges Micha\\u0142 Majchrowicz, Marcin Wyczechowski and Piotr Zdunek (members of the AFINE Team) for bringing this issue to our attention and following the highest standards of coordinated disclosure.\"}], \"metrics\": [{\"format\": \"CVSS\", \"cvssV3_1\": {\"scope\": \"UNCHANGED\", \"version\": \"3.1\", \"baseScore\": 3.1, \"attackVector\": \"NETWORK\", \"baseSeverity\": \"LOW\", \"vectorString\": \"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N\", \"integrityImpact\": \"LOW\", \"userInteraction\": \"REQUIRED\", \"attackComplexity\": \"HIGH\", \"availabilityImpact\": \"NONE\", \"privilegesRequired\": \"NONE\", \"confidentialityImpact\": \"NONE\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"GENERAL\"}]}, {\"format\": \"CVSS\", \"cvssV4_0\": {\"Safety\": \"NOT_DEFINED\", \"version\": \"4.0\", \"Recovery\": \"NOT_DEFINED\", \"baseScore\": 2.3, \"Automatable\": \"NOT_DEFINED\", \"attackVector\": \"NETWORK\", \"baseSeverity\": \"LOW\", \"valueDensity\": \"NOT_DEFINED\", \"vectorString\": \"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N\", \"providerUrgency\": \"NOT_DEFINED\", \"userInteraction\": \"PASSIVE\", \"attackComplexity\": \"HIGH\", \"attackRequirements\": \"NONE\", \"privilegesRequired\": \"NONE\", \"subIntegrityImpact\": \"NONE\", \"vulnIntegrityImpact\": \"LOW\", \"subAvailabilityImpact\": \"NONE\", \"vulnAvailabilityImpact\": \"NONE\", \"subConfidentialityImpact\": \"NONE\", \"vulnConfidentialityImpact\": \"NONE\", \"vulnerabilityResponseEffort\": \"NOT_DEFINED\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"GENERAL\"}]}], \"affected\": [{\"vendor\": \"F5\", \"modules\": [\"All Modules\"], \"product\": \"BIG-IP\", \"versions\": [{\"status\": \"affected\", \"version\": \"21.1.0\", \"lessThan\": \"21.1.0.1\", \"versionType\": \"custom\"}, {\"status\": \"affected\", \"version\": \"21.0.0\", \"lessThan\": \"21.0.0.3\", \"versionType\": \"custom\"}, {\"status\": \"affected\", \"version\": \"17.5.0\", \"lessThan\": \"17.5.1.8\", \"versionType\": \"custom\"}, {\"status\": \"affected\", \"version\": \"17.1.0\", \"lessThan\": \"17.1.3.4\", \"versionType\": \"custom\"}], \"defaultStatus\": \"unknown\"}], \"datePublic\": \"2026-08-19T04:00:00.000Z\", \"references\": [{\"url\": \"https://my.f5.com/manage/s/article/K000161728\", \"tags\": [\"vendor-advisory\"]}], \"workarounds\": [{\"lang\": \"en\", \"value\": \"To mitigate this vulnerability, you may take the following actions:\\n\\n\\nWhen you have finished using the BIG-IP \\nConfiguration utility, you should log off and close all instances of \\nyour web browser. Do not use the same web browser that you use to manage\\n the BIG-IP Configuration utility for any other purposes, such as \\nbrowsing the internet. If you must perform both actions on the same \\nclient machine, F5 recommends that you do so in separate browsers\", \"supportingMedia\": [{\"type\": \"text/html\", \"value\": \"\u003cp\u003eTo mitigate this vulnerability, you may take the following actions:\u003c/p\u003e\\n\u003cp\u003eWhen you have finished using the BIG-IP \\nConfiguration utility, you should log off and close all instances of \\nyour web browser. Do not use the same web browser that you use to manage\\n the BIG-IP Configuration utility for any other purposes, such as \\nbrowsing the internet. If you must perform both actions on the same \\nclient machine, F5 recommends that you do so in separate browsers\u003c/p\u003e\", \"base64\": false}]}], \"x_generator\": {\"engine\": \"F5 SIRTBot v1.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages\\u00a0\\n\\n\\n\\n\\n\\nImpact:\\n\\n\\nAn attacker may trick authenticated BIG-IP users \\ninto accessing malicious links and reflect a spoofed error message in \\nthe victim\u0027s BIG-IP Configuration utility web browser session. This is a\\n control plane issue; there is no data plane exposure.\\n\\n\\n\\n\\n\\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.\", \"supportingMedia\": [{\"type\": \"text/html\", \"value\": \"\u003cdiv\u003eA vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages\u0026nbsp;\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003e\\n\u003cp\u003eImpact:\u003c/p\u003e\\n\u003cp\u003eAn attacker may trick authenticated BIG-IP users \\ninto accessing malicious links and reflect a spoofed error message in \\nthe victim\u0027s BIG-IP Configuration utility web browser session. This is a\\n control plane issue; there is no data plane exposure.\u003c/p\u003e\\n\\n\u003c/div\u003e\u003cdiv\u003eNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.\u003c/div\u003e\", \"base64\": false}]}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"cweId\": \"CWE-451\", \"description\": \"CWE-451: User Interface (UI) Misrepresentation of Critical Information\"}]}], \"providerMetadata\": {\"orgId\": \"9dacffd4-cb11-413f-8451-fbbfd4ddc0ab\", \"shortName\": \"f5\", \"dateUpdated\": \"2026-09-02T15:40:53.437Z\"}}}",
"cveMetadata": "{\"cveId\": \"CVE-2026-63020\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-09-02T17:55:45.119Z\", \"dateReserved\": \"2026-07-24T22:40:21.245Z\", \"assignerOrgId\": \"9dacffd4-cb11-413f-8451-fbbfd4ddc0ab\", \"datePublished\": \"2026-09-02T15:40:53.437Z\", \"assignerShortName\": \"f5\"}",
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
}
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…