LiveActive security incident?Get immediate response
CVE Record

CVE-2019-6626: On BIG-IP (AFM, Analytics, ASM) 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, and 11.5....

On BIG-IP (AFM, Analytics, ASM) 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, and 11.5.1-11.6.3.4, A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Traffic Management User Interface (TMUI), also known as the Configuration utility.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

CVE-2019-6626 is a reflected XSS issue in the F5 BIG-IP TMUI Configuration utility affecting AFM, Analytics, and ASM versions listed by CVE. It could let attacker-supplied content run in a user's browser if the vulnerable interface is reachable and a user is induced to interact. Severity and CVSS details are not provided in the source bundle.

Executive priority

Treat this as a management-plane hygiene issue requiring timely review, especially if BIG-IP administration is widely reachable. It is not supported as actively exploited by the provided sources, but exposed administrative interfaces increase business risk.

Technical view

The CVE describes reflected cross-site scripting on an undisclosed BIG-IP TMUI page for AFM, Analytics, and ASM across 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, and 11.5.1-11.6.3.4. The exact parameter, page, prerequisites, and vendor fix details are not included in the bundle.

Likely exposure

Organizations are most exposed where affected BIG-IP management interfaces are reachable from broad internal networks or the internet. Exposure depends on running the listed BIG-IP AFM, Analytics, or ASM versions and having TMUI accessible to users who could be targeted.

Exploitation context

The source bundle does not show CISA KEV inclusion or any cited active exploitation evidence. Because this is reflected XSS in an administrative web interface, practical risk likely depends on interface reachability and successful user interaction.

Researcher notes

Evidence is limited: no CVSS, CWE, exploit details, or advisory content beyond the F5 URL is included in the bundle. Do not infer the vulnerable endpoint, authentication requirements, or fixed versions without consulting F5 K00432398 directly.

Mitigation direction

  • Review F5 advisory K00432398 for supported fixes and mitigations.
  • Limit TMUI access to trusted administrative networks only.
  • Inventory BIG-IP AFM, Analytics, and ASM versions against affected ranges.
  • Prioritize upgrade or remediation for internet-reachable management interfaces.
  • Monitor vendor guidance for any updated severity or exploit information.

Validation and detection

  • Confirm whether BIG-IP AFM, Analytics, or ASM is deployed.
  • Compare installed versions to the affected ranges in the CVE.
  • Check whether TMUI is reachable from untrusted networks.
  • Review access controls around the Configuration utility.
  • Document remediation status against F5 advisory K00432398.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2019-6626 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
F5BIG-IP (AFM, Analytics, ASM)BIG-IP (AFM, Analytics, ASM) 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.5.1-11.6.3.4Listed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.