When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code
위협 신호 · CVSS · EPSS · KEV
이론적 심각도 점수
예측 데이터 없음
등재일 2026. 09. 22.
패치 기한 2026. 09. 25.
즉시 패치 + 침해 여부 포렌식 분석
CVSS 벡터 · 메트릭
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H약점 (CWE)
- CWE-122
힙 기반 버퍼 오버플로 — 힙 버퍼를 넘쳐 써서 메모리 손상.
상세 설명
When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability.
Impact:
This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AI 심층 분석
공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.
영향받는 제품·버전
- f5 big-ip_access_policy_manager17.0.0 - 17.1.3other
- f5 big-ip_access_policy_manager17.5.0 - 17.5.1other
- f5 big-ip_access_policy_managerother
영향받는 구성 (CPE) 2
- f5 big-ip_access_policy_manager≥ 17.0.0 ≤ 17.1.3cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
- f5 big-ip_access_policy_manager 21.1.0cpe:2.3:a:f5:big-ip_access_policy_manager:21.1.0:*:*:*:*:*:*:*
참고 자료 2
- https://my.f5.com/manage/s/article/K000162605Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-94127US Government Resource
링크 내용 불러오는 중…