CVE-2025-53521
Published Oct 15, 2025
Last updated 6 months ago
AI description
CVE-2025-53521 is a vulnerability affecting F5 BIG-IP Access Policy Manager (APM) systems when an access policy is configured on a virtual server. The flaw, categorized as CWE-770 (Allocation of Resources Without Limits or Throttling), allows undisclosed or specially crafted traffic to cause the Traffic Management Microkernel (TMM) process to terminate. This termination of the TMM process results in a disruption of all traffic handled by the BIG-IP device until the process restarts. The vulnerability can be exploited remotely by an unauthenticated attacker, leading to a denial-of-service condition on the BIG-IP APM system.
- Description
- When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
- Source
- f5sirt@f5.com
- NVD status
- Analyzed
- Products
- big-ip_access_policy_manager
CVSS 4.0
- Type
- Secondary
- Base score
- 9.3
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
Data from CISA
- Vulnerability name
- F5 BIG-IP Unspecified Vulnerability
- Exploit added on
- Mar 27, 2026
- Exploit action due
- Mar 30, 2026
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- f5sirt@f5.com
- CWE-121
- Hype score
- Not currently trending
An F5 BIG-IP APM rootkit (named PoisonedRefresh by ESET) hooks Apache and PHP at runtime to serve a web shell that never touches disk, exploiting CVE-2025-53521, an unauthenticated RCE now in CISA KEV. - CVE-2025-53521 is the door. An unauthenticated RCE in BIG-IP APM, added to
@DFIR_Radar
14 Sept 2026
246 Impressions
1 Retweet
1 Like
1 Bookmark
1 Reply
0 Quotes
🟠 𝗛𝗜𝗚𝗛 · 𝗠𝗮𝗹𝘄𝗮𝗿𝗲 🏢 Target: 𝗙𝟱 𝗡𝗲𝘁𝘄𝗼𝗿𝗸𝘀 A Linux rootkit targeting F5 BIG-IP APM devices has been identified, capable of injecting a web shell into memory without writing to disk. This malware exploits a critic
@intels_daily
11 Sept 2026
121 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️⚠️ CVE-2025-53521 (CVSS 9.8): Unauthenticated RCE in F5 BIG-IP APM (apmd) — now being exploited to drop the PoisonedRefresh memory-only Linux rootkit on SSL-VPN appliances. 🔗FOFA Link: https://t.co/cQvguyFmL5 🎯1.6M+ Results are found on https://t.co/pb16tGXCUG i
@fofabot
11 Sept 2026
2736 Impressions
12 Retweets
31 Likes
16 Bookmarks
0 Replies
0 Quotes
CVE-2025-53521, discovered in October of 2025 as a minor technical glitch, has recently been escalated to CVSS 9.3 due to its ability to perform RCE. This vulnerability affects F5's BIG-IP access policy manager when policies are set on virtual servers. The exploit utilizes a
@Leila97726926
10 Sept 2026
40 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Investigadores de Sophos alertan: el malware c05d5254 esconde una web shell PHP en memoria para evadir escaneos. Los atacantes lo usan tras explotar CVE-2025-53521 (CVSS 9.8) sin login en F5 BIG-IP. Parchea y monitorea. https://t.co/OVG32Sop6G https://t.co/BCYd9lr1Dx
@ProtAAPP
10 Sept 2026
268 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
#threatreport #LowCompleteness Dissecting a PHP web server rootkit | 07-09-2026 Source: https://t.co/uyP062Rd9R Key details below ↓ 💀Threats: Chinachopper, 🎯Victims: Big ip access policy management webtop environments 🔓CVEs: CVE-2025-53521 https://t.co/nQ1MtmVDwo
@rst_cloud
10 Sept 2026
95 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Prasówka 10.09 Wyszedł OpenSSL w wersji 4.1 alpha1: DTLS 1.3, GREASE, IKEv2 KDF, szybsze ML-KEM i ML-DSA. Tylko do testów. PoisonedRefresh: bezplikowy rootkit działający na Apache (CVE-2025-53521) wstrzykuje webshell do pamięci. Update nie pomaga. i-have-adhd: projekt, k
@arkady86
10 Sept 2026
282 Impressions
0 Retweets
1 Like
1 Bookmark
1 Reply
0 Quotes
🟠 𝗛𝗜𝗚𝗛 · 𝗠𝗮𝗹𝘄𝗮𝗿𝗲 🏢 Target: 𝗙𝟱 🧩 Product: 𝗙𝟱 𝗕𝗜𝗚-𝗜𝗣 𝗔𝗣𝗠 A detailed analysis of the PoisonedRefresh Linux implant targeting F5 BIG-IP APM systems, exploiting CVE-2025-53521 for unauthorized command exe
@intels_daily
9 Sept 2026
106 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
TRC analysis shows attackers exploiting CVE-2025-53521 in F5 BIG-IP APM to inject PHP web shells directly into Apache memory, bypassing disk-based detection entirely. The malware hooks system functions to modify scripts in-memory and establishes C2 through disguised HTTP
@aviatrixtrc
9 Sept 2026
50 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
PoisonedRefresh is a fileless Linux implant that provides web-shell and interactive shell access on compromised F5 BIG-IP APM systems. - Initial access exploits unauthenticated remote code execution in CVE-2025-53521. - A first-stage payload modifies system components, SELinux h
@LandscapeThreat
9 Sept 2026
46 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Hackers deployed a Linux rootkit on F5 BIG-IP APM devices, keeping a web shell in memory to evade file-based detection. The campaign is linked to CVE-2025-53521 and PoisonedRefresh. #F5BIGIPAPM #CVE202553521 #PoisonedRefresh https://t.co/eJU8oc0Txk
@TweetThreatNews
9 Sept 2026
207 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
PoisonedRefresh is a fileless Linux rootkit targeting F5 BIG-IP APM, injecting PHP web shells entirely into Apache process memory via CVE-2025-53521, an actively exploited unauthenticated RCE. - CVE-2025-53521 is the initial access vector: an unauthenticated RCE in BIG-IP APM ht
@DFIR_Radar
9 Sept 2026
270 Impressions
1 Retweet
3 Likes
0 Bookmarks
2 Replies
0 Quotes
Sophos found F5 BIG-IP APM malware injecting a PHP web shell into memory, leaving disk files clean. Linked to CVE-2025-53521 and c05d5254, with indicators like apm_css.php3 and full_wt.php3. #F5 #BIGIPAPM #CVE202553521 https://t.co/DmKbsyd2lR
@TweetThreatNews
9 Sept 2026
186 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Alert for admins: new malware infects F5 BIG-IP APM via CVE-2025-53521 — instead of dropping files on disk, it injects a PHP web shell into memory when Apache loads certain scripts (apm_css.php3, full_wt.php3, webtop_popup_css.php3). It also alters core binaries, disables https
@dailytechonx
9 Sept 2026
52 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Sophos found a Linux rootkit in F5 BIG-IP APM that hooks Apache/PHP, injects a fileless web shell into memory, and may follow CVE-2025-53521 exploitation. #F5BIGIP #PoisonedRefresh #CVE202553521 https://t.co/ljBe4l3loX
@TweetThreatNews
8 Sept 2026
198 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔴 F5 BIG-IP APM cihazlarını hedefleyen gelişmiş bir Linux rootkit ortaya çıktı! Sophos araştırmacıları, CVE-2025-53521 sonrasında dağıtıldığı değerlendirilen bir rootkit'in Apache/PHP çalışma mekanizmasını hook ederek belleğe fileless web shell enjekt
@ridvanyagli
8 Sept 2026
324 Impressions
0 Retweets
1 Like
2 Bookmarks
0 Replies
0 Quotes
F5 BIG-IP APM devices are being hit with a Linux rootkit (ESET: PoisonedRefresh) that hooks PHP loading and injects a fileless in-memory web shell. Sophos ties it to post-exploitation of CVE-2025-53521 and notes persistence across BIG-IP upgrade images.
@XavierRiveraX
8 Sept 2026
88 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
News: F5 BIG-IP APM rootkit (PoisonedRefresh) injects a fileless PHP web shell after CVE-2025-53521 RCE. Persists across upgrades. ~795 hosts exposed. Patch APM; watch .php3 POSTs that return HTTP 201 as CSS. https://t.co/9ku4Yl4rvx
@snakeyesV1
8 Sept 2026
93 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
A fileless PHP web shell implant targeting F5 BIG-IP APM systems uses custom ELF loading, APR function hooking, and in-memory mmap patching to deliver attacker access with zero on-disk web shell artifacts. Key findings: - CVE-2025-53521 is the initial access vector: an https://
@DFIR_Radar
7 Sept 2026
194 Impressions
1 Retweet
1 Like
0 Bookmarks
1 Reply
0 Quotes
We are scanning & reporting F5 BIG-IP APM CVE-2025-53521 instances thanks to collaboration with the @ncsc_nl SRT. 10 months after vuln disclosure, we still see over 850 IPs vulnerable to potential RCE. Top affected: US with 199 & Japan 182. IP data in Vulnerable HTTP repo
@Shadowserver
14 Aug 2026
1429 Impressions
5 Retweets
9 Likes
3 Bookmarks
2 Replies
0 Quotes
TRC analysis reveals attackers chaining F5 BIG-IP and Confluence exploits to pivot from edge appliances into Active Directory. CVE-2025-53521 provided initial access, followed by credential harvesting for relay authentication attacks. Runtime segmentation could have limited this
@aviatrixtrc
23 May 2026
267 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Approximately a month ago, F5 published advisory on malware deployed to BIG-IP systems vulnerable to CVE-2025-53521. #ESETresearch discovered two related malware components on VirusTotal and named the threat #PoisonedRefresh. 1/6 https://t.co/OfekbKd8a9
@ESETresearch
24 Apr 2026
4119 Impressions
12 Retweets
36 Likes
15 Bookmarks
1 Reply
1 Quote
🚨 [CRITICAL] Critical RCE Vulnerability in F5 BIG-IP Access Policy Manager Under Active Exploitation The UK NCSC has issued an urgent advisory regarding CVE-2025-53521, an unauthenticated remote code execution vulnerability affecting F5 BIG-IP Access Policy Manager (APM). htt
@HalluG76811
21 Apr 2026
136 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
F5 BIG-IP 긴급 패치, CVE-2025-53521 (출처 : 기록 | https://t.co/4mrWqpidcJ 블로그) https://t.co/nVerHLLeB7
@J_zjaan7946
17 Apr 2026
157 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2025-53521: F5 BIG-IP Unauthenticated RCE — Detection and Emergency Hardeni… "On March 27, 2026, CISA added CVE-2025-53521 to its Known Exploited Vulnerabilities (KEV)…" 🔗 https://t.co/MhFNGwwQQi #CyberSecurity #ThreatIntel #vulnerability #cve
@SecurityAr58409
15 Apr 2026
68 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity Immediate Action Required: Patching F5 BIG-IP APM Against CVE-2025-53521 "The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical security…" 🔗 https://t.co/50qmp9rWtt #CyberSecurity #ThreatIntel #vulnerability #cve #patch
@SecurityAr58409
15 Apr 2026
49 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity Urgent: Defending Against Active Exploitation of F5 BIG-IP APM (CVE-2025-53521) "The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has sounded the alarm by…" 🔗 https://t.co/KdSlD7OTQ2 #CyberSecurity #ThreatIntel #vulnerability #cve #pat
@SecurityAr58409
15 Apr 2026
46 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
F5 has updated its security advisory for a vulnerability impacting BIG-IP APM that was originally disclosed in October 2025 (CVE-2025-53521). Learn more in our latest security bulletin: https://t.co/jmxqUJFEdG
@ChannelSkell
14 Apr 2026
89 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
ثـ ـغرة CVE-2025-53521 في F5 BIG-IP APM تدخل قائمة CISA للثـ ـغرات المستغلة التفاصيل .. https://t.co/Q3M9WECM7s #مركز_الأمن_السيبراني_للابحاث_والدراسات https://t.co/UQ4lP3M55S
@ccforrs
10 Apr 2026
118 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-53521: 2025 vuln, 2026 RCE reclassification, active exploitation. 14K BIG-IP APM instances still on internet. F5 publishes IOCs and says "rebuild." When the vendor says rebuild, patching is theater. Your appliance is compromised. Question: why was it exposed?
@CisoRaging77913
10 Apr 2026
119 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
F5 BIG-IP APM の RCE 脆弱性 CVE-2025-53521:実環境での積極的な悪用を確認 https://t.co/zwywf9Dtu3 この問題の原因は、脆弱性 CVE-2025-53521 に対する初期の分類が、サービス拒否 (DoS) とされていた点にあります。一般的に、
@iototsecnews
10 Apr 2026
198 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
F5 has updated its security advisory regarding a vulnerability affecting BIG-IP APM that was originally disclosed in October 2025 (CVE-2025-53521). For more information, please see our latest security bulletin: https://t.co/ZJHoVjPYXs
@rfrumm
8 Apr 2026
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️ **Vulnerability Alert:** F5 BIG-IP Access Policy Manager Stack-based Buffer Overflow (CVE-2025-53521) — Actively Exploited RCE 📅 **Timeline:** Disclosure: 2025-04-08, Patch: 2025-04-08 🆔 **CVE-2025-53521** | 📊 CVSS: 9.8 (CRITICAL 🔴) | 📈 EPSS: 97.39% 🛠
@syedaquib77
8 Apr 2026
123 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
統合版 JPCERT/CC | Weekly Report: F5 BIG-IP Access Policy Managerの脆弱性(CVE-2025-53521)に関する注意喚起 https://t.co/Qf7Ag9QiAK #itsec_jp
@itsec_jp
8 Apr 2026
158 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️ Stop scrolling if your company uses F5 BIG-IP APM Critical flaw CVE-2025-53521 is now on CISA’s KEV list—and already exploited. Attackers can run code remotely, steal data, and take over systems. Patch immediately. Don’t wait.
@TheCyberse46292
7 Apr 2026
111 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Edge infrastructure is failing first — again. CISA just added two critical flaws to the KEV catalog: • Citrix NetScaler CVE-2026-3055 (memory overread via SAML IdP) • F5 BIG-IP APM CVE-2025-53521 (unauthenticated RCE) Both are actively exploited. New article → htt
@ByteVanguardSec
7 Apr 2026
113 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
F5 hat seinen Sicherheitshinweis zu einer Sicherheitslücke aktualisiert, die BIG-IP APM betrifft und ursprünglich im Oktober 2025 bekannt gegeben wurde (CVE-2025-53521). Weitere Informationen finden Sie in unserem aktuellen Sicherheitsbulletin: https://t.co/ZBCqQ0TS2E
@rfrumm
7 Apr 2026
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Attackers are actively exploiting CVE-2025-53521, a critical RCE in F5 BIG-IP APM, with Shadowserver identifying over 14,000 exposed instances globally after the flaw was reclassified from DoS to remote code execution and added to CISA’s KEV catalog. https://t.co/sNWUY2Y65O
@VivekIntel
6 Apr 2026
165 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
CISA flags active F5 BIG-IP exploit. 🔗 https://t.co/SMp0zi7QPO CVE-2025-53521 enables unauthenticated remote code execution and full system compromise. KEV listing means urgent patching is required. #MADSecurity #CISA #Cybersecurity #VulnerabilityManagement
@MADSecurityLLC
6 Apr 2026
119 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️ Threat Update: F5 BIG-IP APM RCE Exploitation (CVE-2025-53521) 📝 Key Updates Summary: NEW: CVE-2025-53521 was reclassified in Mar 2026 from DoS to unauthenticated RCE and added to CISA's KEV (3/27/2026) with a federal remediation directive. NEW: Shadowserver snapshots
@syedaquib77
6 Apr 2026
151 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
【F5 BIG-IP APMの重大RCE、14,000超がなお露出】 F5 BIG-IP APMのRCE脆弱性 CVE-2025-53521 はすでに悪用が確認されており、なお14,000台超の公開インスタンスが残っていると報じられています。 未認証RCEにつながる深刻な
@01ra66it
6 Apr 2026
276 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
⚠️ Threat Update: Active Exploitation of CVE-2025-53521 Against F5 BIG-IP APM 📝 Key Updates Summary: NEW: 2026-04-06 incoming report corroborates active exploitation of CVE-2025-53521 and provides a Shadowserver exposure snapshot (~14,100 exposed APM fingerprints across
@syedaquib77
6 Apr 2026
128 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Attackers Exploit RCE Flaw as 14,000 F5 BIG-IP APM Instances Remain Exposed: Over 14,000 F5 BIG-IP APM instances remain exposed online, as attackers actively exploit a critical remote code execution flaw CVE-2025-53521. Over 14,000 F5 BIG-IP APM… https://t.co/zpLPylrt46 https:/
@shah_sheikh
6 Apr 2026
113 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[Security Affairs] Attackers Exploit RCE Flaw as 14,000 F5 BIG-IP APM Instances Remain Exposed. Over 14,000 F5 BIG-IP APM instances remain exposed online, as attackers actively exploit a critical remote code execution flaw CVE-2025-53521. Over 14,000... https://t.co/sqwmBHZnU3
@shah_sheikh
6 Apr 2026
108 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
turns into an actively exploited F5 BIG-IP APM… (CVE-2025-53521) is a good reminder that this vulnerability can turn edge and identity infrastructure into a much bigger remote code execution problem. For defenders, the priority is to validate exposure, watch for suspic…
@SocXAInvaders
6 Apr 2026
137 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
turns into an actively exploited F5 BIG-IP APM… (CVE-2025-53521) is a vulnerability story defenders should take serious… F5 has reclassified the vulnerability from a denial of service issue to remote code execution , confirmed exp…
@fynn_JourX
6 Apr 2026
136 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
For defenders, cve-2025-53521 turns into an actively exploited f5 big-ip apm r… should move fast. F5 reclassified CVE-2025-53521 from DoS to remote code execution, CISA added it to KEV, and… 🔗 Details → https://t.co/ivyyW0SUmB
@SocXAInvaders
6 Apr 2026
133 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Legacy exposure keeps paying off for attackers. CVE-2025-53521 turns into an actively exploited F5 BIG-IP… F5 reclassified CVE-2025-53521 from DoS to remote code execution, CISA added it to KEV, and… 🔗 Read → https://t.co/qAubleY76J
@fynn_JourX
6 Apr 2026
132 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
turns into an actively exploited F5 BIG-IP APM… (CVE-2025-53521) deserves defender attention because this vulnerability… F5 has reclassified the vulnerability from a denial of service issue to remote code execution , confirmed exp…
@lucasverdan
6 Apr 2026
159 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🛑 CVE-2025-53521 turns into an actively exploited F5 BIG-IP APM RCE F5 reclassified CVE-2025-53521 from DoS to remote code execution, CISA added it to KEV, and… 🔗 Details → https://t.co/TUf0xBbEnS
@lucasverdan
6 Apr 2026
136 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "A7A0C1CA-EDEF-463F-B7C8-8B9E67239FC1",
"versionEndExcluding": "15.1.10.8",
"versionStartIncluding": "15.1.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "6494E2A7-1473-46C0-97F8-90827D9466AA",
"versionEndExcluding": "16.1.6.1",
"versionStartIncluding": "16.1.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "96D35435-27A7-4A88-9432-1F5AB0112B8C",
"versionEndExcluding": "17.1.3",
"versionStartIncluding": "17.1.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "252ED1A4-5F29-4440-B1BA-9621E6791812",
"versionEndExcluding": "17.5.1.3",
"versionStartIncluding": "17.5.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]