{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-63020",
        "assignerOrgId": "9dacffd4-cb11-413f-8451-fbbfd4ddc0ab",
        "state": "PUBLISHED",
        "assignerShortName": "f5",
        "dateReserved": "2026-07-24T22:40:21.245Z",
        "datePublished": "2026-09-02T15:40:53.437Z",
        "dateUpdated": "2026-09-02T17:55:45.119Z"
    },
    "containers": {
        "cna": {
            "affected": [
                {
                    "defaultStatus": "unknown",
                    "modules": [
                        "All Modules"
                    ],
                    "product": "BIG-IP",
                    "vendor": "F5",
                    "versions": [
                        {
                            "lessThan": "21.1.0.1",
                            "status": "affected",
                            "version": "21.1.0",
                            "versionType": "custom"
                        },
                        {
                            "lessThan": "21.0.0.3",
                            "status": "affected",
                            "version": "21.0.0",
                            "versionType": "custom"
                        },
                        {
                            "lessThan": "17.5.1.8",
                            "status": "affected",
                            "version": "17.5.0",
                            "versionType": "custom"
                        },
                        {
                            "lessThan": "17.1.3.4",
                            "status": "affected",
                            "version": "17.1.0",
                            "versionType": "custom"
                        }
                    ]
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "type": "finder",
                    "value": "F5 acknowledges Michał Majchrowicz, Marcin Wyczechowski and Piotr Zdunek  (members of the AFINE Team) for bringing this issue to our attention and following the highest standards of coordinated disclosure."
                }
            ],
            "datePublic": "2026-08-19T04:00:00.000Z",
            "descriptions": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "<div>A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages&nbsp;</div><div><br></div><div>\n<p>Impact:</p>\n<p>An attacker may trick authenticated BIG-IP users \ninto accessing malicious links and reflect a spoofed error message in \nthe victim's BIG-IP Configuration utility web browser session. This is a\n control plane issue; there is no data plane exposure.</p>\n\n</div><div>Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</div>"
                        }
                    ],
                    "value": "A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages \n\n\n\n\n\nImpact:\n\n\nAn attacker may trick authenticated BIG-IP users \ninto accessing malicious links and reflect a spoofed error message in \nthe victim's BIG-IP Configuration utility web browser session. This is a\n control plane issue; there is no data plane exposure.\n\n\n\n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "attackComplexity": "HIGH",
                        "attackVector": "NETWORK",
                        "availabilityImpact": "NONE",
                        "baseScore": 3.1,
                        "baseSeverity": "LOW",
                        "confidentialityImpact": "NONE",
                        "integrityImpact": "LOW",
                        "privilegesRequired": "NONE",
                        "scope": "UNCHANGED",
                        "userInteraction": "REQUIRED",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N",
                        "version": "3.1"
                    },
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ]
                },
                {
                    "cvssV4_0": {
                        "Automatable": "NOT_DEFINED",
                        "Recovery": "NOT_DEFINED",
                        "Safety": "NOT_DEFINED",
                        "attackComplexity": "HIGH",
                        "attackRequirements": "NONE",
                        "attackVector": "NETWORK",
                        "baseScore": 2.3,
                        "baseSeverity": "LOW",
                        "privilegesRequired": "NONE",
                        "providerUrgency": "NOT_DEFINED",
                        "subAvailabilityImpact": "NONE",
                        "subConfidentialityImpact": "NONE",
                        "subIntegrityImpact": "NONE",
                        "userInteraction": "PASSIVE",
                        "valueDensity": "NOT_DEFINED",
                        "vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
                        "version": "4.0",
                        "vulnAvailabilityImpact": "NONE",
                        "vulnConfidentialityImpact": "NONE",
                        "vulnIntegrityImpact": "LOW",
                        "vulnerabilityResponseEffort": "NOT_DEFINED"
                    },
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ]
                }
            ],
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "cweId": "CWE-451",
                            "description": "CWE-451: User Interface (UI) Misrepresentation of Critical Information",
                            "lang": "en",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "providerMetadata": {
                "orgId": "9dacffd4-cb11-413f-8451-fbbfd4ddc0ab",
                "shortName": "f5",
                "dateUpdated": "2026-09-02T15:40:53.437Z"
            },
            "references": [
                {
                    "tags": [
                        "vendor-advisory"
                    ],
                    "url": "https://my.f5.com/manage/s/article/K000161728"
                }
            ],
            "source": {
                "discovery": "EXTERNAL"
            },
            "title": "BIG-IP Configuration utility vulnerability",
            "workarounds": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "<p>To mitigate this vulnerability, you may take the following actions:</p>\n<p>When you have finished using the BIG-IP \nConfiguration utility, you should log off and close all instances of \nyour web browser. Do not use the same web browser that you use to manage\n the BIG-IP Configuration utility for any other purposes, such as \nbrowsing the internet. If you must perform both actions on the same \nclient machine, F5 recommends that you do so in separate browsers</p>"
                        }
                    ],
                    "value": "To mitigate this vulnerability, you may take the following actions:\n\n\nWhen you have finished using the BIG-IP \nConfiguration utility, you should log off and close all instances of \nyour web browser. Do not use the same web browser that you use to manage\n the BIG-IP Configuration utility for any other purposes, such as \nbrowsing the internet. If you must perform both actions on the same \nclient machine, F5 recommends that you do so in separate browsers"
                }
            ],
            "x_generator": {
                "engine": "F5 SIRTBot v1.0"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2026-09-02T17:55:36.352848Z",
                                "id": "CVE-2026-63020",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2026-09-02T17:55:45.119Z"
                }
            }
        ]
    }
}