CVE-2026-42937: 
F5 BIG-IP Virtual Edition Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-42937 is an incorrect permission assignment vulnerability affecting F5 BIG-IP and BIG-IQ products, specifically in the TMOS Shell (tmsh) arp and ndp commands and in BIG-IP iControl REST. The vulnerability allows an authenticated attacker with low privileges to view adjacent network information that should be restricted to higher privilege levels. It was published on May 13, 2026, with a patch made available the same day. Affected versions include BIG-IP 16.1.0 and later (up to fixed versions), BIG-IP 17.1.0 < 17.1.3.2, BIG-IP 17.5.0 < 17.5.1.6, BIG-IP 21.0.0 < 21.0.0.2, and BIG-IQ 8.4.0 and later. The CVSS v3.1 base score is 6.5 (Medium) and the CVSS v4.0 base score is 7.1 (High) (GitHub Advisory, F5 Advisory).

Détails techniques

The root cause is classified as CWE-732 (Incorrect Permission Assignment for Critical Resource), where the arp and ndp commands in the BIG-IP/BIG-IQ TMOS Shell and the iControl REST API are configured with permissions that allow lower-privileged authenticated users to access information intended only for higher-privileged roles. An attacker with valid, low-privilege credentials can invoke these commands or REST endpoints over the network without any user interaction, obtaining adjacent network topology data such as ARP and NDP table entries. No special attack complexity or prerequisites beyond valid credentials are required (GitHub Advisory, F5 Advisory).

Impact

Successful exploitation results in unauthorized disclosure of adjacent network information, including ARP and NDP table data, which could reveal network topology, IP-to-MAC address mappings, and neighboring device details. There is no integrity or availability impact — the vulnerability is limited to confidentiality. While the scope is constrained to adjacent network information, this data could assist an attacker in further reconnaissance or lateral movement within the network environment (GitHub Advisory, F5 Advisory).

Exploitabilité

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of publication (GitHub Advisory). The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.041–0.051%, placing it in the 16th percentile for exploitation likelihood within 30 days. No threat actor attribution has been reported.

Étapes d’exploitation

  1. Obtain valid credentials: Acquire low-privilege authenticated credentials for a BIG-IP or BIG-IQ system running an affected version (e.g., through phishing, credential stuffing, or insider access).
  2. Access tmsh or iControl REST: Log in to the TMOS Shell (tmsh) via SSH or access the iControl REST API endpoint using the obtained credentials.
  3. Execute restricted commands: Run the arp or ndp commands within tmsh, or issue equivalent iControl REST API requests (e.g., GET /mgmt/tm/net/arp or GET /mgmt/tm/net/ndp) that should be restricted to higher-privilege roles.
  4. Collect adjacent network information: Review the output, which reveals ARP/NDP table entries including IP addresses, MAC addresses, and interface associations of adjacent network devices.
  5. Use data for further reconnaissance: Leverage the disclosed network topology information to identify additional targets or plan lateral movement within the network (GitHub Advisory, F5 Advisory).

Indicateurs de compromis

  • Logs: BIG-IP audit logs showing low-privilege user accounts executing arp or ndp commands in tmsh; iControl REST access logs recording GET requests to /mgmt/tm/net/arp or /mgmt/tm/net/ndp by accounts not expected to access these endpoints.
  • Network: Unusual or repeated REST API queries to ARP/NDP endpoints from authenticated sessions associated with low-privilege service or operator accounts.
  • Behavioral: Low-privilege user accounts accessing network information commands outside of normal administrative workflows or at unusual times.

Atténuation et solutions de contournement

F5 has released patched versions: BIG-IP 17.1.3.2, 17.5.1.6, and 21.0.0.2. Organizations should upgrade to these fixed versions as the primary remediation. As an interim workaround, restrict access to tmsh arp and ndp commands and iControl REST endpoints to only users who legitimately require access to adjacent network information, and audit user role assignments to enforce least-privilege principles (F5 Advisory, GitHub Advisory).

Ressources additionnelles


Source: Ce rapport a été généré à l’aide de l’IA

Apparenté F5 BIG-IP Virtual Edition Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-42920HIGH8.7
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NonOuiMay 13, 2026
CVE-2026-42930HIGH8.5
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_application_security_manager
NonOuiMay 13, 2026
CVE-2026-42924HIGH8.5
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_application_security_manager
NonOuiMay 13, 2026
CVE-2026-42937HIGH7.1
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NonOuiMay 13, 2026
CVE-2026-63020LOW2.3
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NonOuiSep 02, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités