peter bassill · operator
$ cve CVE-2016-5700 JSON

CVE-2016-5700

9.8
CRITICAL · CVSS 3.0 · EPSS 6.4% (pctl 94)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Virtual servers in F5 BIG-IP systems 11.5.0, 11.5.1 before HF11, 11.5.2, 11.5.3, 11.5.4 before HF2, 11.6.0 before HF8, 11.6.1 before HF1, 12.0.0 before HF4, and 12.1.0 before HF2, when configured with the HTTP Explicit Proxy functionality or SOCKS profile, allow remote attackers to modify the system configuration, read system files, and possibly execute arbitrary code via unspecified vectors.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS6.42% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-284
On CISA KEVno
Public exploitnone known
Published2016-10-03
Last modified2026-06-17

Affected (8)

VendorProduct
f5big-ip access policy manager
f5big-ip advanced firewall manager
f5big-ip application acceleration manager
f5big-ip application security manager
f5big-ip link controller
f5big-ip local traffic manager
f5big-ip policy enforcement manager
f5big-ip websafe

References

→ the Explorer  ·  watch your stack  ·  NVD