8.7

CVE-2026-40629

BIG-IP SSL/TLS vulnerability

When SSL profiles are configured on a virtual server, undisclosed traffic can cause the virtual server to stop processing new client connections.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerF5
Produkt BIG-IP
Default Statusunknown
Version 21.0.0
Version < *
Status unaffected
Version 17.5.0
Version < 17.5.1.4
Status affected
Version 17.1.0
Version < 17.1.3.1
Status affected
Version 16.1.0
Version < *
Status affected
HerstellerF5
Produkt BIG-IP Next SPK
Default Statusunknown
Version 2.0.0
Version < 2.0.3
Status affected
Version 1.7.0
Version < 1.7.16
Status affected
HerstellerF5
Produkt BIG-IP Next CNF
Default Statusunknown
Version 2.0.0
Version < 2.0.3
Status affected
Version 1.1.0
Version < 1.4.1
Status affected
HerstellerF5
Produkt BIG-IP Next for Kubernetes
Default Statusunknown
Version 2.0.0
Version < 2.1.1
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.07% 0.218
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
f5sirt@f5.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
f5sirt@f5.com 8.7 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-770 Allocation of Resources Without Limits or Throttling

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.