Security Advisory

CVE-2026-42937

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-05-13 14:12:40
Last updated 2026-05-13 16:09:45
Assigner f5
CVSS score 6.5
State PUBLISHED

Description

Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) arp and ndp commands, and in BIG-IP iControl REST. These vulnerabilities may allow an authenticated attacker to view adjacent network information.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.