← Vulnerability feed

Vulnerability record · CVE-2019-6630 · published 3 July 2019

CVE-2019-6630: F5 ssl orchestrator vulnerability

F5 · Ssl Orchestrator

On F5 SSL Orchestrator 14.1.0-14.1.0.5 and 14.0.0-14.0.0.4, undisclosed traffic flow may cause TMM to restart under certain circumstances.

7.5 CVSS 3.0 High EPSS 1.4% · top 28.8%
7.5CVSS 3.0 base score, v2 5.0
1.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

On F5 SSL Orchestrator 14.1.0-14.1.0.5 and 14.0.0-14.0.0.4, undisclosed traffic flow may cause TMM to restart under certain circumstances.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-6630 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-22991F5 BIG-IP TMM URI normalization buffer overflowF5 BIG-IP's Traffic Management Microkernel (TMM) mishandles URI normalization for undisclosed requests to a virtual server, triggering a buffer overf…KEVEPSS 61%analysed9.8CVE-2021-22986F5 BIG-IP iControl REST unauthenticated remote command executionThe iControl REST interface on multiple F5 BIG-IP and BIG-IQ versions exposes an unauthenticated remote command execution flaw, tracked as CWE-918 se…KEVEPSS 100%analysed9.8CVE-2020-5902F5 BIG-IP TMUI path traversal leading to remote code executionThe F5 BIG-IP Traffic Management User Interface (TMUI, also called the Configuration utility) contains a path traversal flaw (CWE-22) in undisclosed …KEVEPSS 100%analysed9.9CVE-2021-22987F5 big-ip access policy manager vulnerabilityOn BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x b…EPSS 14%9.8CVE-2021-22992F5 BIG-IP ASM/Advanced WAF Login Page Buffer OverflowA buffer overflow exists in F5 BIG-IP Advanced WAF/BIG-IP ASM virtual servers that have a Login Page configured in their policy. A malicious HTTP res…EPSS 73%analysed9.1CVE-2021-22989F5 big-ip access policy manager vulnerabilityOn BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x b…EPSS 8.8%8.8CVE-2021-22988F5 big-ip access policy manager vulnerabilityOn BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x b…EPSS 10%8.8CVE-2020-5922F5 big-ip access policy manager cross-site request forgery vulnerabilityIn BIG-IP versions 15.0.0-15.1.0.4, 14.1.0-14.1.2.6, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2, iControl REST does not implement Cross Si…EPSS 0.59%

Source: NIST National Vulnerability Database (record CVE-2019-6630), CISA KEV, FIRST EPSS (scores of 2026-10-08). This page is refreshed as NVD updates the record.