{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2026-42408",
        "tracking": {
            "current_release_date": "2026-05-15T12:13:41.926962Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2026-42408",
            "initial_release_date": "2026-05-13T15:47:43.809997Z",
            "revision_history": [
                {
                    "date": "2026-05-13T15:47:43.809997Z",
                    "number": "1",
                    "summary": "CVE created.| Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (4).| References created (1).| CWES updated (1)."
                },
                {
                    "date": "2026-05-13T15:47:45.508688Z",
                    "number": "2",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-05-13T17:08:54.307987Z",
                    "number": "3",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (1).| CWES updated (1)."
                },
                {
                    "date": "2026-05-13T17:08:56.327017Z",
                    "number": "4",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-05-13T17:58:24.524755Z",
                    "number": "5",
                    "summary": "Unknown change."
                },
                {
                    "date": "2026-05-13T18:49:00.145643Z",
                    "number": "6",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (1).| Product Threats created (1).| Product Remediations created (1).| Products connected (15).| CWES updated (1)."
                },
                {
                    "date": "2026-05-13T18:49:08.604617Z",
                    "number": "7",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-05-14T15:07:54.055099Z",
                    "number": "8",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-05-14T15:08:05.413657Z",
                    "number": "9",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-05-15T10:12:10.642254Z",
                    "number": "10",
                    "summary": "Source connected.| CVE status created. (valid)| Products connected (10).| References created (60)."
                },
                {
                    "date": "2026-05-15T10:12:13.377905Z",
                    "number": "11",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-05-15T12:13:37.499237Z",
                    "number": "12",
                    "summary": "Source connected.| CVE status created. (valid)"
                }
            ],
            "status": "interim",
            "version": "12"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-5529241"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "AI Gateway"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/16.1.0|<*",
                                "product": {
                                    "name": "vers:unknown/16.1.0|<*",
                                    "product_id": "CSAFPID-1968133"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/17.1.0|<17.1.3.1",
                                "product": {
                                    "name": "vers:unknown/17.1.0|<17.1.3.1",
                                    "product_id": "CSAFPID-5525263"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/17.5.0|<17.5.1.4",
                                "product": {
                                    "name": "vers:unknown/17.5.0|<17.5.1.4",
                                    "product_id": "CSAFPID-5525262"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/21.0.0|<*",
                                "product": {
                                    "name": "vers:unknown/21.0.0|<*",
                                    "product_id": "CSAFPID-5525261"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/advanced wafasm",
                                "product": {
                                    "name": "vers:unknown/advanced wafasm",
                                    "product_id": "CSAFPID-7067500",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:f5:big-ip:advanced_wafasm"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/apm",
                                "product": {
                                    "name": "vers:unknown/apm",
                                    "product_id": "CSAFPID-7067497",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:f5:big-ip:apm"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/ddos hybrid defender",
                                "product": {
                                    "name": "vers:unknown/ddos hybrid defender",
                                    "product_id": "CSAFPID-7067499",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:f5:big-ip:ddos_hybrid_defender"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/dns",
                                "product": {
                                    "name": "vers:unknown/dns",
                                    "product_id": "CSAFPID-7067496",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:f5:big-ip:dns"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/next cnf",
                                "product": {
                                    "name": "vers:unknown/next cnf",
                                    "product_id": "CSAFPID-7067503",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:f5:big-ip:next_cnf"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/next for kubernetes",
                                "product": {
                                    "name": "vers:unknown/next for kubernetes",
                                    "product_id": "CSAFPID-7067502",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:f5:big-ip:next_for_kubernetes"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/next spk",
                                "product": {
                                    "name": "vers:unknown/next spk",
                                    "product_id": "CSAFPID-7067501",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:f5:big-ip:next_spk"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/pem",
                                "product": {
                                    "name": "vers:unknown/pem",
                                    "product_id": "CSAFPID-7067498",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:f5:big-ip:pem"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/ssl orchestrator",
                                "product": {
                                    "name": "vers:unknown/ssl orchestrator",
                                    "product_id": "CSAFPID-7067495",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:f5:big-ip:ssl_orchestrator"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "BIG-IP"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-5529247"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "BIG-IP (all other modules)"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/17.1.3.1",
                                "product": {
                                    "name": "vers:unknown/17.1.3.1",
                                    "product_id": "CSAFPID-7047290"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/17.5.1.4",
                                "product": {
                                    "name": "vers:unknown/17.5.1.4",
                                    "product_id": "CSAFPID-7047289"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=17.1.0|<=17.1.3|>=17.5.0|<=17.5.1",
                                "product": {
                                    "name": "vers:unknown/>=17.1.0|<=17.1.3|>=17.5.0|<=17.5.1",
                                    "product_id": "CSAFPID-7047291"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "BIG-IP DNS"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-5529231"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "BIG-IP Next CNF"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-5529230"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "BIG-IP Next SPK"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-5529232"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "BIG-IP Next for Kubernetes"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-525430"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "BIG-IQ Centralized Management"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-5529234"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Distributed Cloud (all services)"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/unknown",
                                "product": {
                                    "name": "vers:unknown/unknown",
                                    "product_id": "CSAFPID-1330602",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:f5:big-ip:-"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "F5 BIG-IP"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-5529248"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "NGINX (all products)"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-5529236"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "NGINX One Console"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-5529237"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "OS-A"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-5529238"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "OS-C"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-5529235"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Silverline (all services)"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-5529240"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Traffix SDC"
                    }
                ],
                "category": "vendor",
                "name": "F5"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-42408",
            "cwe": {
                "id": "CWE-312",
                "name": "Cleartext Storage of Sensitive Information"
            },
            "notes": [
                {
                    "category": "description",
                    "text": "When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed TMOS Shell (tmsh) command that may allow a highly privileged authenticated attacker to view sensitive information.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.",
                    "title": "cveprojectv5 - https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/42xxx/CVE-2026-42408.json"
                },
                {
                    "category": "description",
                    "text": "When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed TMOS Shell (tmsh) command that may allow a highly privileged authenticated attacker to view sensitive information.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.",
                    "title": "nvd - https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-42408"
                },
                {
                    "category": "description",
                    "text": "When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed TMOS Shell (**tmsh**) command that may allow a highly privileged authenticated attacker to view sensitive information.",
                    "title": "f5 - https://my.f5.com/manage/s/article/K000157981"
                },
                {
                    "category": "other",
                    "text": "0.00014",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
                    "title": "CVSSV4"
                },
                {
                    "category": "other",
                    "text": "6.7",
                    "title": "CVSSV4 base score"
                },
                {
                    "category": "other",
                    "text": "5.0",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "VENDOR FIX as product remediation category, There is product data available from source Certbundde",
                    "title": "NCSC Score top increasing factors"
                },
                {
                    "category": "other",
                    "text": "The value of the most recent EPSS score, Is related to (a version of) an uncommon product, There is cwe data available from source Nvd",
                    "title": "NCSC Score top decreasing factors"
                }
            ],
            "product_status": {
                "fixed": [
                    "CSAFPID-7047289",
                    "CSAFPID-7047290"
                ],
                "known_affected": [
                    "CSAFPID-1968133",
                    "CSAFPID-5525262",
                    "CSAFPID-5525263",
                    "CSAFPID-7047291",
                    "CSAFPID-1330602",
                    "CSAFPID-7067495",
                    "CSAFPID-7067496",
                    "CSAFPID-7067497",
                    "CSAFPID-7067498",
                    "CSAFPID-7067499",
                    "CSAFPID-7067500",
                    "CSAFPID-7067501",
                    "CSAFPID-7067502",
                    "CSAFPID-7067503"
                ],
                "known_not_affected": [
                    "CSAFPID-5525261",
                    "CSAFPID-525430",
                    "CSAFPID-5529230",
                    "CSAFPID-5529231",
                    "CSAFPID-5529232",
                    "CSAFPID-5529234",
                    "CSAFPID-5529235",
                    "CSAFPID-5529236",
                    "CSAFPID-5529237",
                    "CSAFPID-5529238",
                    "CSAFPID-5529240",
                    "CSAFPID-5529241",
                    "CSAFPID-5529247",
                    "CSAFPID-5529248"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/42xxx/CVE-2026-42408.json"
                },
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-42408"
                },
                {
                    "category": "external",
                    "summary": "Source - f5",
                    "url": "https://my.f5.com/manage/s/article/K000157981"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1532.json"
                },
                {
                    "category": "external",
                    "summary": "Source - ncscclear",
                    "url": "https://advisories.ncsc.nl/advisory?id=NCSC-2026-0162"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde; cveprojectv5; nvd",
                    "url": "https://my.f5.com/manage/s/article/K000157981"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1532.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1532"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://my.f5.com/manage/s/article/K000149743"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://my.f5.com/manage/s/article/K000156734"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://my.f5.com/manage/s/article/K000157895"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://my.f5.com/manage/s/article/K000158038"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://my.f5.com/manage/s/article/K000160862"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://my.f5.com/manage/s/article/K000160863"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://my.f5.com/manage/s/article/K000160874"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://my.f5.com/manage/s/article/K000160876"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://my.f5.com/manage/s/article/K000160903"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://my.f5.com/manage/s/article/K000160911"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://my.f5.com/manage/s/article/K000160916"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://my.f5.com/manage/s/article/K000160945"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://my.f5.com/manage/s/article/K000160971"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://my.f5.com/manage/s/article/K000160972"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://my.f5.com/manage/s/article/K000161018"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://my.f5.com/manage/s/article/K000160981"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://my.f5.com/manage/s/article/K000160979"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://my.f5.com/manage/s/article/K000160973"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://my.f5.com/manage/s/article/K000161040"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://my.f5.com/manage/s/article/K000161022"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://my.f5.com/manage/s/article/K000161107"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://my.f5.com/manage/s/article/K32950402"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://my.f5.com/manage/s/article/K000160975"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://my.f5.com/manage/s/article/K000160857"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://my.f5.com/manage/s/article/K000158978"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://my.f5.com/manage/s/article/K000158070"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://my.f5.com/manage/s/article/K000156761"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://my.f5.com/manage/s/article/K000158082"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://my.f5.com/manage/s/article/K000156581"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://my.f5.com/manage/s/article/K000156604"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://my.f5.com/manage/s/article/K000160926"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://my.f5.com/manage/s/article/K000160901"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://my.f5.com/manage/s/article/K000158971"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://my.f5.com/manage/s/article/K000159034"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://my.f5.com/manage/s/article/K000158979"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://my.f5.com/manage/s/article/K000160875"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://my.f5.com/manage/s/article/K35544022"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://my.f5.com/manage/s/article/K000161023"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://my.f5.com/manage/s/article/K000161056"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://my.f5.com/manage/s/article/K000160788"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://my.f5.com/manage/s/article/K000160727"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://euvd.enisa.europa.eu/enisa/EUVD-2026-29965"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://euvd.enisa.europa.eu/enisa/EUVD-2026-29969"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://euvd.enisa.europa.eu/enisa/EUVD-2026-29971"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://euvd.enisa.europa.eu/enisa/EUVD-2026-29972"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://euvd.enisa.europa.eu/enisa/EUVD-2026-29982"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://euvd.enisa.europa.eu/enisa/EUVD-2026-29984"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://euvd.enisa.europa.eu/enisa/EUVD-2026-29987"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://euvd.enisa.europa.eu/enisa/EUVD-2026-29998"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://euvd.enisa.europa.eu/enisa/EUVD-2026-29999"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://euvd.enisa.europa.eu/enisa/EUVD-2026-30003"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://euvd.enisa.europa.eu/enisa/EUVD-2026-30004"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://euvd.enisa.europa.eu/enisa/EUVD-2026-30005"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://euvd.enisa.europa.eu/enisa/EUVD-2026-29973"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://euvd.enisa.europa.eu/enisa/EUVD-2026-29975"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://euvd.enisa.europa.eu/enisa/EUVD-2026-29976"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://euvd.enisa.europa.eu/enisa/EUVD-2026-29991"
                }
            ],
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Update to version 17.1.3.1 or 17.5.1.4.",
                    "product_ids": [
                        "CSAFPID-7047291"
                    ]
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
                        "baseScore": 4.4,
                        "baseSeverity": "MEDIUM"
                    },
                    "products": [
                        "CSAFPID-1330602",
                        "CSAFPID-1968133",
                        "CSAFPID-5525262",
                        "CSAFPID-5525263",
                        "CSAFPID-7047291",
                        "CSAFPID-7067495",
                        "CSAFPID-7067496",
                        "CSAFPID-7067497",
                        "CSAFPID-7067498",
                        "CSAFPID-7067499",
                        "CSAFPID-7067500",
                        "CSAFPID-7067501",
                        "CSAFPID-7067502",
                        "CSAFPID-7067503"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "details": "An authenticated attacker with Resource Administrator role privileges may exploit the vulnerability through a **tmsh** command. If the exploit is successful, an attacker can view sensitive information in the **tmsh** command line history output. In addition, the audit log displays passwords in cleartext. The Auditor, Log Administrator, Resource Administrator, and Administrator BIG-IP user roles have access to the audit log by default. There is no data plane exposure; this is a control plane issue only.",
                    "product_ids": [
                        "CSAFPID-7047291"
                    ]
                }
            ],
            "title": "CVE-2026-42408"
        }
    ]
}