CVE-2013-3587
Estado: ModificadaMedia (5.9)—
The HTTPS protocol, as used in unspecified web applications, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which makes it easier for man-in-the-middle attackers to obtain plaintext secret values by observing length differences during a series of guesses in which a string in an HTTP request URL potentially matches an unknown string in an HTTP response body, aka a "BREACH" attack, a different issue than CVE-2012-4929.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 5.9
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 6.05%
- Percentil entre todas las CVEs puntuadas: 93
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (14)
F5 — ARXF5 — Big-ip Access Policy ManagerF5 — Big-ip Advanced Firewall ManagerF5 — Big-ip AnalyticsF5 — Big-ip Application Acceleration ManagerF5 — Big-ip Application Security ManagerF5 — Big-ip Edge GatewayF5 — Big-ip Link ControllerF5 — Big-ip Local Traffic ManagerF5 — Big-ip Policy Enforcement ManagerF5 — Big-ip Protocol Security ModuleF5 — Big-ip WAN Optimization ManagerF5 — Big-ip WebacceleratorF5 — Firepass
CWE
- CWE-200
Referencias
- http://breachattack.com/
- http://github.com/meldium/breach-mitigation-rails
- http://security.stackexchange.com/questions/20406/is-http-compression-safe#20407
- http://slashdot.org/story/13/08/05/233216
- http://www.iacr.org/cryptodb/archive/2002/FSE/3091/3091.pdf
- http://www.kb.cert.org/vuls/id/987798
- https://bugzilla.redhat.com/show_bug.cgi?id=995168
- https://hackerone.com/reports/254895
- https://lists.apache.org/thread.html/r7f0e9cfd166934172d43ca4c272b8bdda4a343036229d9937affd1e1%40%3Cdev.httpd.apache.org%3E
- https://support.f5.com/csp/article/K14634
- https://www.blackhat.com/us-13/briefings.html#Prado
- https://www.djangoproject.com/weblog/2013/aug/06/breach-and-django/
- http://breachattack.com/
- http://github.com/meldium/breach-mitigation-rails
- http://security.stackexchange.com/questions/20406/is-http-compression-safe#20407
- http://slashdot.org/story/13/08/05/233216
- http://www.iacr.org/cryptodb/archive/2002/FSE/3091/3091.pdf
- http://www.kb.cert.org/vuls/id/987798
- https://bugzilla.redhat.com/show_bug.cgi?id=995168
- https://hackerone.com/reports/254895
- https://lists.apache.org/thread.html/r7f0e9cfd166934172d43ca4c272b8bdda4a343036229d9937affd1e1%40%3Cdev.httpd.apache.org%3E
- https://support.f5.com/csp/article/K14634
- https://www.blackhat.com/us-13/briefings.html#Prado
- https://www.djangoproject.com/weblog/2013/aug/06/breach-and-django/
JSON original (NVD)
Mostrar
{
"id": "CVE-2013-3587",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.9,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 2.2
}
]
},
"affected": [
{
"source": "cret@cert.org",
"affectedData": [
{
"vendor": "n/a",
"product": "HTTPS protocol",
"versions": [
{
"status": "affected",
"version": "all"
}
]
}
]
}
],
"published": "2020-02-21T18:15:11.427",
"references": [
{
"url": "http://breachattack.com/",
"tags": [
"Third Party Advisory"
],
"source": "cret@cert.org"
},
{
"url": "http://github.com/meldium/breach-mitigation-rails",
"tags": [
"Third Party Advisory"
],
"source": "cret@cert.org"
},
{
"url": "http://security.stackexchange.com/questions/20406/is-http-compression-safe#20407",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "cret@cert.org"
},
{
"url": "http://slashdot.org/story/13/08/05/233216",
"tags": [
"Third Party Advisory"
],
"source": "cret@cert.org"
},
{
"url": "http://www.iacr.org/cryptodb/archive/2002/FSE/3091/3091.pdf",
"tags": [
"Third Party Advisory"
],
"source": "cret@cert.org"
},
{
"url": "http://www.kb.cert.org/vuls/id/987798",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "cret@cert.org"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=995168",
"tags": [
"Issue Tracking",
"Third Party Advisory"
],
"source": "cret@cert.org"
},
{
"url": "https://hackerone.com/reports/254895",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "cret@cert.org"
},
{
"url": "https://lists.apache.org/thread.html/r7f0e9cfd166934172d43ca4c272b8bdda4a343036229d9937affd1e1%40%3Cdev.httpd.apache.org%3E",
"source": "cret@cert.org"
},
{
"url": "https://support.f5.com/csp/article/K14634",
"tags": [
"Third Party Advisory"
],
"source": "cret@cert.org"
},
{
"url": "https://www.blackhat.com/us-13/briefings.html#Prado",
"tags": [
"Third Party Advisory"
],
"source": "cret@cert.org"
},
{
"url": "https://www.djangoproject.com/weblog/2013/aug/06/breach-and-django/",
"tags": [
"Third Party Advisory"
],
"source": "cret@cert.org"
},
{
"url": "http://breachattack.com/",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://github.com/meldium/breach-mitigation-rails",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://security.stackexchange.com/questions/20406/is-http-compression-safe#20407",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://slashdot.org/story/13/08/05/233216",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.iacr.org/cryptodb/archive/2002/FSE/3091/3091.pdf",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.kb.cert.org/vuls/id/987798",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=995168",
"tags": [
"Issue Tracking",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://hackerone.com/reports/254895",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://lists.apache.org/thread.html/r7f0e9cfd166934172d43ca4c272b8bdda4a343036229d9937affd1e1%40%3Cdev.httpd.apache.org%3E",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://support.f5.com/csp/article/K14634",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.blackhat.com/us-13/briefings.html#Prado",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.djangoproject.com/weblog/2013/aug/06/breach-and-django/",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The HTTPS protocol, as used in unspecified web applications, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which makes it easier for man-in-the-middle attackers to obtain plaintext secret values by observing length differences during a series of guesses in which a string in an HTTP request URL potentially matches an unknown string in an HTTP response body, aka a \"BREACH\" attack, a different issue than CVE-2012-4929."
},
{
"lang": "es",
"value": "El protocolo HTTPS, como es usado en aplicaciones web no especificadas, puede cifrar datos comprimidos sin ofuscar apropiadamente la longitud de los datos no cifrados, facilitando a atacantes de tipo \"man-in-the-middle\" obtener valores secretos en texto plano al observar las diferencias de longitud durante una serie de adivinaciones en las que una cadena en una URL de peticiones HTTP coincide potencialmente con una cadena desconocida en un cuerpo de respuesta HTTP, también se conoce como ataque \"BREACH\", un problema diferente de CVE-2012-4929."
}
],
"lastModified": "2026-06-16T23:55:28.233",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "79618AB4-7A8E-4488-8608-57EC2F8681FE",
"versionEndIncluding": "10.2.4",
"versionStartIncluding": "10.1.0"
},
{
"criteria": "cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "57AB5137-9797-4BA3-8725-40494DA8FFB2",
"versionEndIncluding": "11.6.1",
"versionStartIncluding": "11.0.0"
},
{
"criteria": "cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0ACC0695-E62E-4748-AA8A-46772EB8C83C",
"versionEndIncluding": "12.1.2",
"versionStartIncluding": "12.0.0"
},
{
"criteria": "cpe:2.3:a:f5:big-ip_access_policy_manager:13.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BCF89E7C-806E-4800-BAA9-0225433B6C56"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "59217FC1-AFB3-479F-A369-9C7FB3DD29F0",
"versionEndIncluding": "11.6.1",
"versionStartIncluding": "11.3.0"
},
{
"criteria": "cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "93212B86-21EA-4340-9149-E58F65285C15",
"versionEndIncluding": "12.1.2",
"versionStartIncluding": "12.0.0"
},
{
"criteria": "cpe:2.3:a:f5:big-ip_advanced_firewall_manager:13.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8C4E5F36-434B-48E1-9715-4EEC22FB23D1"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0FCA781F-8728-4ECB-85D1-1E0AE4EEFC2B",
"versionEndIncluding": "11.6.1",
"versionStartIncluding": "11.0.0"
},
{
"criteria": "cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "25944BCA-3EEB-4396-AC8F-EF58834BC47E",
"versionEndIncluding": "12.1.2",
"versionStartIncluding": "12.0.0"
},
{
"criteria": "cpe:2.3:a:f5:big-ip_analytics:13.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "34D75E7F-B65F-421D-92EE-6B20756019C2"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "70FB5FD7-4B96-438C-AAD3-D2E128DAA8BF",
"versionEndIncluding": "11.6.1",
"versionStartIncluding": "11.4.0"
},
{
"criteria": "cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "39E45CF5-C9E4-4AB9-A6D5-66F8336DDB79",
"versionEndIncluding": "12.1.2",
"versionStartIncluding": "12.0.0"
},
{
"criteria": "cpe:2.3:a:f5:big-ip_application_acceleration_manager:13.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3D75D5AD-C20A-4D94-84E0-E695C9D2A26D"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6034A531-6A0E-4086-A76F-91C3F62C7994",
"versionEndIncluding": "9.4.8",
"versionStartIncluding": "9.2.0"
},
{
"criteria": "cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "667D3780-3949-41AC-83DE-5BCB8B36C382",
"versionEndIncluding": "10.2.4",
"versionStartIncluding": "10.0.0"
},
{
"criteria": "cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FDDD9D77-12B6-40F4-B819-2515D357A91A",
"versionEndIncluding": "11.6.1",
"versionStartIncluding": "11.0.0"
},
{
"criteria": "cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7CB146EF-CCAB-4194-9735-F8909E283308",
"versionEndIncluding": "12.1.2",
"versionStartIncluding": "12.0.0"
},
{
"criteria": "cpe:2.3:a:f5:big-ip_application_security_manager:13.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7569977A-E567-4115-B00C-4B0CBA86582E"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:f5:big-ip_edge_gateway:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A8347412-DC42-4B86-BF6E-A44A5E1541ED",
"versionEndIncluding": "10.2.4",
"versionStartIncluding": "10.1.0"
},
{
"criteria": "cpe:2.3:a:f5:big-ip_edge_gateway:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C8942D9D-8E3A-4876-8E93-ED8D201FF546",
"versionEndIncluding": "11.3.0",
"versionStartIncluding": "11.0.0"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E27C5743-4F94-4A1C-AD8C-25D29B65BF95",
"versionEndIncluding": "9.4.8",
"versionStartIncluding": "9.2.2"
},
{
"criteria": "cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1DF6BB8A-FA63-4DBC-891C-256FF23CBCF0",
"versionEndIncluding": "10.2.4",
"versionStartIncluding": "10.0.0"
},
{
"criteria": "cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1D413BDC-8B60-494A-A218-75EAF09D1495",
"versionEndIncluding": "11.6.1",
"versionStartIncluding": "11.0.0"
},
{
"criteria": "cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C4A5CD9B-D257-4EC9-8C57-D9552C2FFFFC",
"versionEndIncluding": "12.1.2",
"versionStartIncluding": "12.0.0"
},
{
"criteria": "cpe:2.3:a:f5:big-ip_link_controller:13.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E2C4414E-8016-48B5-8CC3-F97FF2D85922"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5F293F06-4601-4074-A695-2C229CF8D126",
"versionEndIncluding": "9.6.1",
"versionStartIncluding": "9.0.0"
},
{
"criteria": "cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "289CEABB-22A2-436D-AE4B-4BDA2D0EAFDB",
"versionEndIncluding": "10.2.4",
"versionStartIncluding": "10.0.0"
},
{
"criteria": "cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "439927F5-ECDA-4DD8-BA75-97E55C9E584F",
"versionEndIncluding": "11.6.1",
"versionStartIncluding": "11.0.0"
},
{
"criteria": "cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C1F5FF67-5D17-4760-AFDC-4234EC1E6306",
"versionEndIncluding": "12.1.2",
"versionStartIncluding": "12.0.0"
},
{
"criteria": "cpe:2.3:a:f5:big-ip_local_traffic_manager:13.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BA7D64DC-7271-4617-BD46-99C8246779CA"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "632BD15C-04E6-4FD9-9410-6DE9E48F926A",
"versionEndIncluding": "11.6.1",
"versionStartIncluding": "11.3.0"
},
{
"criteria": "cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BDE77CCE-7F97-48EA-A9D3-090B1481616F",
"versionEndIncluding": "12.1.2",
"versionStartIncluding": "12.0.0"
},
{
"criteria": "cpe:2.3:a:f5:big-ip_policy_enforcement_manager:13.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "42821916-E601-4831-B37B-3202ACF2C562"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:f5:big-ip_protocol_security_module:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5522F58E-C4EA-40B4-8F44-3E95315D37EA",
"versionEndIncluding": "9.4.8",
"versionStartIncluding": "9.4.5"
},
{
"criteria": "cpe:2.3:a:f5:big-ip_protocol_security_module:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2C0B4C01-C71E-4E35-B63A-68395984E033",
"versionEndIncluding": "10.2.4",
"versionStartIncluding": "10.0.0"
},
{
"criteria": "cpe:2.3:a:f5:big-ip_protocol_security_module:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9828CBA5-BB72-46E2-987D-633A5B3E2AFF",
"versionEndIncluding": "11.4.1",
"versionStartIncluding": "11.0.0"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:f5:big-ip_wan_optimization_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BB60C39D-52ED-47DD-9FB9-2B4BC8D9F8AC",
"versionEndIncluding": "10.2.4",
"versionStartIncluding": "10.0.0"
},
{
"criteria": "cpe:2.3:a:f5:big-ip_wan_optimization_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "68BC025A-D45E-45FB-A4E4-1C89320B5BBE",
"versionEndIncluding": "11.3.0",
"versionStartIncluding": "11.0.0"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3F383EBC-4739-4514-9EC0-BE17AC453735",
"versionEndIncluding": "9.4.8",
"versionStartIncluding": "9.4.0"
},
{
"criteria": "cpe:2.3:a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AE007A64-5867-4B1A-AEFB-3AB2CD6A5EA4",
"versionEndIncluding": "10.2.4",
"versionStartIncluding": "10.0.0"
},
{
"criteria": "cpe:2.3:a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7C75978B-566B-4353-8716-099CB8790EE0",
"versionEndIncluding": "11.3.0",
"versionStartIncluding": "11.0.0"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:f5:firepass:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "15CE213B-F42C-4C2E-AFBD-852AB049FF8A",
"versionEndIncluding": "6.1.0",
"versionStartIncluding": "6.0.0"
},
{
"criteria": "cpe:2.3:a:f5:firepass:7.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "442D343A-973B-4C33-B99B-1EA2B7670DE5"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:f5:arx:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "794651B6-E22C-4A6F-9B1F-AA94BEDD44FF",
"versionEndIncluding": "5.3.1",
"versionStartIncluding": "5.0.0"
},
{
"criteria": "cpe:2.3:a:f5:arx:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F20E6644-F925-4283-AD92-7B0696F52310",
"versionEndIncluding": "6.4.0",
"versionStartIncluding": "6.0.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cret@cert.org"
}