
PEACH
Un cadre d’isolation des locataires
CVE-2026-42937 is an incorrect permission assignment vulnerability affecting F5 BIG-IP and BIG-IQ products, specifically in the TMOS Shell (tmsh) arp and ndp commands and in BIG-IP iControl REST. The vulnerability allows an authenticated attacker with low privileges to view adjacent network information that should be restricted to higher privilege levels. It was published on May 13, 2026, with a patch made available the same day. Affected versions include BIG-IP 16.1.0 and later (up to fixed versions), BIG-IP 17.1.0 < 17.1.3.2, BIG-IP 17.5.0 < 17.5.1.6, BIG-IP 21.0.0 < 21.0.0.2, and BIG-IQ 8.4.0 and later. The CVSS v3.1 base score is 6.5 (Medium) and the CVSS v4.0 base score is 7.1 (High) (GitHub Advisory, F5 Advisory).
The root cause is classified as CWE-732 (Incorrect Permission Assignment for Critical Resource), where the arp and ndp commands in the BIG-IP/BIG-IQ TMOS Shell and the iControl REST API are configured with permissions that allow lower-privileged authenticated users to access information intended only for higher-privileged roles. An attacker with valid, low-privilege credentials can invoke these commands or REST endpoints over the network without any user interaction, obtaining adjacent network topology data such as ARP and NDP table entries. No special attack complexity or prerequisites beyond valid credentials are required (GitHub Advisory, F5 Advisory).
Successful exploitation results in unauthorized disclosure of adjacent network information, including ARP and NDP table data, which could reveal network topology, IP-to-MAC address mappings, and neighboring device details. There is no integrity or availability impact — the vulnerability is limited to confidentiality. While the scope is constrained to adjacent network information, this data could assist an attacker in further reconnaissance or lateral movement within the network environment (GitHub Advisory, F5 Advisory).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of publication (GitHub Advisory). The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.041–0.051%, placing it in the 16th percentile for exploitation likelihood within 30 days. No threat actor attribution has been reported.
arp or ndp commands within tmsh, or issue equivalent iControl REST API requests (e.g., GET /mgmt/tm/net/arp or GET /mgmt/tm/net/ndp) that should be restricted to higher-privilege roles.arp or ndp commands in tmsh; iControl REST access logs recording GET requests to /mgmt/tm/net/arp or /mgmt/tm/net/ndp by accounts not expected to access these endpoints.F5 has released patched versions: BIG-IP 17.1.3.2, 17.5.1.6, and 21.0.0.2. Organizations should upgrade to these fixed versions as the primary remediation. As an interim workaround, restrict access to tmsh arp and ndp commands and iControl REST endpoints to only users who legitimately require access to adjacent network information, and audit user role assignments to enforce least-privilege principles (F5 Advisory, GitHub Advisory).
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."