An authenticated remote code execution vulnerability through undisclosed vectors exists in the BIG-IP and BIG-IQ Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Update F5/BIG-IP to 17.5.1.4; F5/BIG-IQ to 8.4.1 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanBIG-IP and BIG-IQ Configuration utility vulnerability affects F5/BIG-IP (generic), F5/BIG-IQ (generic). Severity is high. An authenticated remote code execution vulnerability through undisclosed vectors exists in the BIG-IP and BIG-IQ Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| F5/BIG-IPgeneric | >=17.5.0 <17.5.1.4 || >=17.1.0 <17.1.3.1 || >=16.1.0 <* | 17.5.1.4, 17.1.3.1, * |
| F5/BIG-IQ |
An authenticated remote code execution vulnerability through undisclosed vectors exists in the BIG-IP and BIG-IQ Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Update F5/BIG-IP to 17.5.1.4; F5/BIG-IQ to 8.4.1 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanBIG-IP and BIG-IQ Configuration utility vulnerability affects F5/BIG-IP (generic), F5/BIG-IQ (generic). Severity is high. An authenticated remote code execution vulnerability through undisclosed vectors exists in the BIG-IP and BIG-IQ Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| F5/BIG-IPgeneric | >=17.5.0 <17.5.1.4 || >=17.1.0 <17.1.3.1 || >=16.1.0 <* | 17.5.1.4, 17.1.3.1, * |
| F5/BIG-IQ |
| >=8.4.0 <8.4.1 |
| 8.4.1 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| >=8.4.0 <8.4.1 |
| 8.4.1 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard