← Vulnerability feed

Vulnerability record · CVE-2017-6130 · published 6 April 2017

CVE-2017-6130: F5 ssl intercept iapp server-side request forgery (ssrf) vulnerability

F5 · Ssl Intercept Iapp

F5 SSL Intercept iApp 1.5.0 - 1.5.7 and SSL Orchestrator 2.0 is vulnerable to a Server-Side Request Forgery (SSRF) attack when deployed using the Dynamic Domain Bypass (DDB) feature feature plus SNAT Auto Map option for egress traffic.

7.4 CVSS 3.0 High EPSS 1.1% · top 34.2% CWE-918 · Server-side request forgery (SSRF)
7.4CVSS 3.0 base score, v2 5.8
1.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

F5 SSL Intercept iApp 1.5.0 - 1.5.7 and SSL Orchestrator 2.0 is vulnerable to a Server-Side Request Forgery (SSRF) attack when deployed using the Dynamic Domain Bypass (DDB) feature feature plus SNAT Auto Map option for egress traffic.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-6130 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-22991F5 BIG-IP TMM URI normalization buffer overflowF5 BIG-IP's Traffic Management Microkernel (TMM) mishandles URI normalization for undisclosed requests to a virtual server, triggering a buffer overf…KEVEPSS 61%analysed9.8CVE-2021-22986F5 BIG-IP iControl REST unauthenticated remote command executionThe iControl REST interface on multiple F5 BIG-IP and BIG-IQ versions exposes an unauthenticated remote command execution flaw, tracked as CWE-918 se…KEVEPSS 100%analysed9.8CVE-2020-5902F5 BIG-IP TMUI path traversal leading to remote code executionThe F5 BIG-IP Traffic Management User Interface (TMUI, also called the Configuration utility) contains a path traversal flaw (CWE-22) in undisclosed …KEVEPSS 100%analysed9.9CVE-2021-22987F5 big-ip access policy manager vulnerabilityOn BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x b…EPSS 14%9.8CVE-2021-22992F5 BIG-IP ASM/Advanced WAF Login Page Buffer OverflowA buffer overflow exists in F5 BIG-IP Advanced WAF/BIG-IP ASM virtual servers that have a Login Page configured in their policy. A malicious HTTP res…EPSS 73%analysed9.8CVE-2017-0305F5 ssl intercept iapp vulnerabilityF5 SSL Intercept iApp version 1.5.0 - 1.5.7 is vulnerable to an unauthenticated, remote attack that may allow modification of the BIG-IP system confi…EPSS 3.8%9.1CVE-2021-22989F5 big-ip access policy manager vulnerabilityOn BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x b…EPSS 8.8%8.8CVE-2021-22988F5 big-ip access policy manager vulnerabilityOn BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x b…EPSS 10%

Source: NIST National Vulnerability Database (record CVE-2017-6130), CISA KEV, FIRST EPSS (scores of 2026-10-08). This page is refreshed as NVD updates the record.