Security readout for executives and security teams
Plain-English summary
CVE-2019-6626 is a reflected XSS issue in the F5 BIG-IP TMUI Configuration utility affecting AFM, Analytics, and ASM versions listed by CVE. It could let attacker-supplied content run in a user's browser if the vulnerable interface is reachable and a user is induced to interact. Severity and CVSS details are not provided in the source bundle.
Executive priority
Treat this as a management-plane hygiene issue requiring timely review, especially if BIG-IP administration is widely reachable. It is not supported as actively exploited by the provided sources, but exposed administrative interfaces increase business risk.
Technical view
The CVE describes reflected cross-site scripting on an undisclosed BIG-IP TMUI page for AFM, Analytics, and ASM across 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, and 11.5.1-11.6.3.4. The exact parameter, page, prerequisites, and vendor fix details are not included in the bundle.
Likely exposure
Organizations are most exposed where affected BIG-IP management interfaces are reachable from broad internal networks or the internet. Exposure depends on running the listed BIG-IP AFM, Analytics, or ASM versions and having TMUI accessible to users who could be targeted.
Exploitation context
The source bundle does not show CISA KEV inclusion or any cited active exploitation evidence. Because this is reflected XSS in an administrative web interface, practical risk likely depends on interface reachability and successful user interaction.
Researcher notes
Evidence is limited: no CVSS, CWE, exploit details, or advisory content beyond the F5 URL is included in the bundle. Do not infer the vulnerable endpoint, authentication requirements, or fixed versions without consulting F5 K00432398 directly.
Mitigation direction
- Review F5 advisory K00432398 for supported fixes and mitigations.
- Limit TMUI access to trusted administrative networks only.
- Inventory BIG-IP AFM, Analytics, and ASM versions against affected ranges.
- Prioritize upgrade or remediation for internet-reachable management interfaces.
- Monitor vendor guidance for any updated severity or exploit information.
Validation and detection
- Confirm whether BIG-IP AFM, Analytics, or ASM is deployed.
- Compare installed versions to the affected ranges in the CVE.
- Check whether TMUI is reachable from untrusted networks.
- Review access controls around the Configuration utility.
- Document remediation status against F5 advisory K00432398.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2019-6626 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://support.f5.com/csp/article/K00432398CVE reference · x_refsource_CONFIRM
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
