F5 BIG-IP LTM, Analytics, APM, ASM, and Link Controller 11.2.x before 11.2.1 HF16, 11.3.x, 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.6.1 HF1, and 12.x before 12.0.0 HF3; BIG-IP AAM, AFM, and PEM 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.6.1 HF1, and 12.x before 12.0.0 HF3; BIG-IP DNS 12.x before 12.0.0 HF3; BIG-IP Edge Gateway, WebAccelerator, and WOM 11.2.x before 11.2.1 HF16 and 11.3.0; BIG-IP GTM 11.2.x before 11.2.1 HF16, 11.3.x, 11.4.x, 11.5.x before 11.5.4 HF2, and 11.6.x before 11.6.1 HF1; BIG-IP PSM 11.2.x before 11.2.1 HF16, 11.3.x, and 11.4.0 through 11.4.1; Enterprise Manager 3.1.1; BIG-IQ Cloud and Security 4.0.0 through 4.5.0; BIG-IQ Device 4.2.0 through 4.5.0; BIG-IQ ADC 4.5.0; BIG-IQ Centralized Management 5.0.0; BIG-IQ Cloud and Orchestration 1.0.0; and iWorkflow 2.0.0, when Packet Filtering is enabled on virtual servers and possibly self IP addresses, allow remote attackers to cause a denial of service (Traffic Management Microkernel restart) and possibly have unspecified other impact via crafted network traffic.
Conclusion & alert: CVE-2016-5022 is rated High Risk (70/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 3.07%). Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-10-23 | 2.43% | 3.07% | +0.65% |
| 2 | 2025-09-16 | 1.30% | 2.43% | +1.12% |
| 3 | 2025-03-30 | — | 1.30% | — |
Full EPSS history (9 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.0 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| 7.5 | 2.0 | HIGH |
|
10.0 | 6.4 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| f5 | big-ip_link_controller | 11.2.0 | cpe:2.3:a:f5:big-ip_link_controller:11.2.0:*:*:*:*:*:*:* |
| f5 | big-ip_link_controller | 11.2.1 | cpe:2.3:a:f5:big-ip_link_controller:11.2.1:*:*:*:*:*:*:* |
| f5 | big-ip_link_controller | 11.3.0 | cpe:2.3:a:f5:big-ip_link_controller:11.3.0:*:*:*:*:*:*:* |
| f5 | big-ip_link_controller | 11.4.0 | cpe:2.3:a:f5:big-ip_link_controller:11.4.0:*:*:*:*:*:*:* |
| f5 | big-ip_link_controller | 11.4.1 | cpe:2.3:a:f5:big-ip_link_controller:11.4.1:*:*:*:*:*:*:* |
| f5 | big-ip_link_controller | 11.5.0 | cpe:2.3:a:f5:big-ip_link_controller:11.5.0:*:*:*:*:*:*:* |
| f5 | big-ip_link_controller | 11.5.1 | cpe:2.3:a:f5:big-ip_link_controller:11.5.1:*:*:*:*:*:*:* |
| f5 | big-ip_link_controller | 11.5.2 | cpe:2.3:a:f5:big-ip_link_controller:11.5.2:*:*:*:*:*:*:* |
| f5 | big-ip_link_controller | 11.5.3 | cpe:2.3:a:f5:big-ip_link_controller:11.5.3:*:*:*:*:*:*:* |
| f5 | big-ip_link_controller | 11.5.4 | cpe:2.3:a:f5:big-ip_link_controller:11.5.4:*:*:*:*:*:*:* |
| f5 | big-ip_link_controller | 11.6.0 | cpe:2.3:a:f5:big-ip_link_controller:11.6.0:*:*:*:*:*:*:* |
| f5 | big-ip_link_controller | 11.6.1 | cpe:2.3:a:f5:big-ip_link_controller:11.6.1:*:*:*:*:*:*:* |
| f5 | big-ip_link_controller | 12.0.0 | cpe:2.3:a:f5:big-ip_link_controller:12.0.0:*:*:*:*:*:*:* |
| f5 | big-ip_policy_enforcement_manager | 11.4.0 | cpe:2.3:a:f5:big-ip_policy_enforcement_manager:11.4.0:*:*:*:*:*:*:* |
| f5 | big-ip_policy_enforcement_manager | 11.4.1 | cpe:2.3:a:f5:big-ip_policy_enforcement_manager:11.4.1:*:*:*:*:*:*:* |
| f5 | big-ip_policy_enforcement_manager | 11.5.0 | cpe:2.3:a:f5:big-ip_policy_enforcement_manager:11.5.0:*:*:*:*:*:*:* |
| f5 | big-ip_policy_enforcement_manager | 11.5.1 | cpe:2.3:a:f5:big-ip_policy_enforcement_manager:11.5.1:*:*:*:*:*:*:* |
| f5 | big-ip_policy_enforcement_manager | 11.5.2 | cpe:2.3:a:f5:big-ip_policy_enforcement_manager:11.5.2:*:*:*:*:*:*:* |
| f5 | big-ip_policy_enforcement_manager | 11.5.3 | cpe:2.3:a:f5:big-ip_policy_enforcement_manager:11.5.3:*:*:*:*:*:*:* |
| f5 | big-ip_policy_enforcement_manager | 11.5.4 | cpe:2.3:a:f5:big-ip_policy_enforcement_manager:11.5.4:*:*:*:*:*:*:* |
| f5 | big-ip_policy_enforcement_manager | 11.6.0 | cpe:2.3:a:f5:big-ip_policy_enforcement_manager:11.6.0:*:*:*:*:*:*:* |
| f5 | big-ip_policy_enforcement_manager | 11.6.1 | cpe:2.3:a:f5:big-ip_policy_enforcement_manager:11.6.1:*:*:*:*:*:*:* |
| f5 | big-ip_policy_enforcement_manager | 12.0.0 | cpe:2.3:a:f5:big-ip_policy_enforcement_manager:12.0.0:*:*:*:*:*:*:* |
| f5 | big-ip_access_policy_manager | 11.2.0 | cpe:2.3:a:f5:big-ip_access_policy_manager:11.2.0:*:*:*:*:*:*:* |
| f5 | big-ip_access_policy_manager | 11.2.1 | cpe:2.3:a:f5:big-ip_access_policy_manager:11.2.1:*:*:*:*:*:*:* |
| f5 | big-ip_access_policy_manager | 11.3.0 | cpe:2.3:a:f5:big-ip_access_policy_manager:11.3.0:*:*:*:*:*:*:* |
| f5 | big-ip_access_policy_manager | 11.4.0 | cpe:2.3:a:f5:big-ip_access_policy_manager:11.4.0:*:*:*:*:*:*:* |
| f5 | big-ip_access_policy_manager | 11.4.1 | cpe:2.3:a:f5:big-ip_access_policy_manager:11.4.1:*:*:*:*:*:*:* |
| f5 | big-ip_access_policy_manager | 11.5.0 | cpe:2.3:a:f5:big-ip_access_policy_manager:11.5.0:*:*:*:*:*:*:* |
| f5 | big-ip_access_policy_manager | 11.5.1 | cpe:2.3:a:f5:big-ip_access_policy_manager:11.5.1:*:*:*:*:*:*:* |
| f5 | big-ip_access_policy_manager | 11.5.2 | cpe:2.3:a:f5:big-ip_access_policy_manager:11.5.2:*:*:*:*:*:*:* |
| f5 | big-ip_access_policy_manager | 11.5.3 | cpe:2.3:a:f5:big-ip_access_policy_manager:11.5.3:*:*:*:*:*:*:* |
| f5 | big-ip_access_policy_manager | 11.5.4 | cpe:2.3:a:f5:big-ip_access_policy_manager:11.5.4:*:*:*:*:*:*:* |
| f5 | big-ip_access_policy_manager | 11.6.0 | cpe:2.3:a:f5:big-ip_access_policy_manager:11.6.0:*:*:*:*:*:*:* |
| f5 | big-ip_access_policy_manager | 11.6.1 | cpe:2.3:a:f5:big-ip_access_policy_manager:11.6.1:*:*:*:*:*:*:* |
| f5 | big-ip_access_policy_manager | 12.0.0 | cpe:2.3:a:f5:big-ip_access_policy_manager:12.0.0:*:*:*:*:*:*:* |
| f5 | big-ip_global_traffic_manager | 11.2.0 | cpe:2.3:a:f5:big-ip_global_traffic_manager:11.2.0:*:*:*:*:*:*:* |
| f5 | big-ip_global_traffic_manager | 11.2.1 | cpe:2.3:a:f5:big-ip_global_traffic_manager:11.2.1:*:*:*:*:*:*:* |
| f5 | big-ip_global_traffic_manager | 11.3.0 | cpe:2.3:a:f5:big-ip_global_traffic_manager:11.3.0:*:*:*:*:*:*:* |
| f5 | big-ip_global_traffic_manager | 11.4.0 | cpe:2.3:a:f5:big-ip_global_traffic_manager:11.4.0:*:*:*:*:*:*:* |
| f5 | big-ip_global_traffic_manager | 11.4.1 | cpe:2.3:a:f5:big-ip_global_traffic_manager:11.4.1:*:*:*:*:*:*:* |
| f5 | big-ip_global_traffic_manager | 11.5.0 | cpe:2.3:a:f5:big-ip_global_traffic_manager:11.5.0:*:*:*:*:*:*:* |
| f5 | big-ip_global_traffic_manager | 11.5.1 | cpe:2.3:a:f5:big-ip_global_traffic_manager:11.5.1:*:*:*:*:*:*:* |
| f5 | big-ip_global_traffic_manager | 11.5.2 | cpe:2.3:a:f5:big-ip_global_traffic_manager:11.5.2:*:*:*:*:*:*:* |
| f5 | big-ip_global_traffic_manager | 11.5.3 | cpe:2.3:a:f5:big-ip_global_traffic_manager:11.5.3:*:*:*:*:*:*:* |
| f5 | big-ip_global_traffic_manager | 11.5.4 | cpe:2.3:a:f5:big-ip_global_traffic_manager:11.5.4:*:*:*:*:*:*:* |
| f5 | big-ip_global_traffic_manager | 11.6.0 | cpe:2.3:a:f5:big-ip_global_traffic_manager:11.6.0:*:*:*:*:*:*:* |
| f5 | big-ip_global_traffic_manager | 11.6.1 | cpe:2.3:a:f5:big-ip_global_traffic_manager:11.6.1:*:*:*:*:*:*:* |
| f5 | big-iq_cloud | 4.0.0 | cpe:2.3:a:f5:big-iq_cloud:4.0.0:*:*:*:*:*:*:* |
| f5 | big-iq_cloud | 4.1.0 | cpe:2.3:a:f5:big-iq_cloud:4.1.0:*:*:*:*:*:*:* |
| f5 | big-iq_cloud | 4.2.0 | cpe:2.3:a:f5:big-iq_cloud:4.2.0:*:*:*:*:*:*:* |
| f5 | big-iq_cloud | 4.3.0 | cpe:2.3:a:f5:big-iq_cloud:4.3.0:*:*:*:*:*:*:* |
| f5 | big-iq_cloud | 4.4.0 | cpe:2.3:a:f5:big-iq_cloud:4.4.0:*:*:*:*:*:*:* |
| f5 | big-iq_cloud | 4.5.0 | cpe:2.3:a:f5:big-iq_cloud:4.5.0:*:*:*:*:*:*:* |
| f5 | big-ip_webaccelerator | 11.2.0 | cpe:2.3:a:f5:big-ip_webaccelerator:11.2.0:*:*:*:*:*:*:* |
| f5 | big-ip_webaccelerator | 11.2.1 | cpe:2.3:a:f5:big-ip_webaccelerator:11.2.1:*:*:*:*:*:*:* |
| f5 | big-ip_webaccelerator | 11.3.0 | cpe:2.3:a:f5:big-ip_webaccelerator:11.3.0:*:*:*:*:*:*:* |
| f5 | big-iq_application_delivery_controller | 4.5.0 | cpe:2.3:a:f5:big-iq_application_delivery_controller:4.5.0:*:*:*:*:*:*:* |
| f5 | big-ip_application_security_manager | 11.2.0 | cpe:2.3:a:f5:big-ip_application_security_manager:11.2.0:*:*:*:*:*:*:* |
| f5 | big-ip_application_security_manager | 11.2.1 | cpe:2.3:a:f5:big-ip_application_security_manager:11.2.1:*:*:*:*:*:*:* |
| f5 | big-ip_application_security_manager | 11.3.0 | cpe:2.3:a:f5:big-ip_application_security_manager:11.3.0:*:*:*:*:*:*:* |
| f5 | big-ip_application_security_manager | 11.4.0 | cpe:2.3:a:f5:big-ip_application_security_manager:11.4.0:*:*:*:*:*:*:* |
| f5 | big-ip_application_security_manager | 11.4.1 | cpe:2.3:a:f5:big-ip_application_security_manager:11.4.1:*:*:*:*:*:*:* |
| f5 | big-ip_application_security_manager | 11.5.0 | cpe:2.3:a:f5:big-ip_application_security_manager:11.5.0:*:*:*:*:*:*:* |
| f5 | big-ip_application_security_manager | 11.5.1 | cpe:2.3:a:f5:big-ip_application_security_manager:11.5.1:*:*:*:*:*:*:* |
| f5 | big-ip_application_security_manager | 11.5.2 | cpe:2.3:a:f5:big-ip_application_security_manager:11.5.2:*:*:*:*:*:*:* |
| f5 | big-ip_application_security_manager | 11.5.3 | cpe:2.3:a:f5:big-ip_application_security_manager:11.5.3:*:*:*:*:*:*:* |
| f5 | big-ip_application_security_manager | 11.5.4 | cpe:2.3:a:f5:big-ip_application_security_manager:11.5.4:*:*:*:*:*:*:* |
| f5 | big-ip_application_security_manager | 11.6.0 | cpe:2.3:a:f5:big-ip_application_security_manager:11.6.0:*:*:*:*:*:*:* |
| f5 | big-ip_application_security_manager | 11.6.1 | cpe:2.3:a:f5:big-ip_application_security_manager:11.6.1:*:*:*:*:*:*:* |
| f5 | big-ip_application_security_manager | 12.0.0 | cpe:2.3:a:f5:big-ip_application_security_manager:12.0.0:*:*:*:*:*:*:* |
| f5 | big-ip_local_traffic_manager | 11.2.0 | cpe:2.3:a:f5:big-ip_local_traffic_manager:11.2.0:*:*:*:*:*:*:* |
| f5 | big-ip_local_traffic_manager | 11.2.1 | cpe:2.3:a:f5:big-ip_local_traffic_manager:11.2.1:*:*:*:*:*:*:* |
| f5 | big-ip_local_traffic_manager | 11.3.0 | cpe:2.3:a:f5:big-ip_local_traffic_manager:11.3.0:*:*:*:*:*:*:* |
| f5 | big-ip_local_traffic_manager | 11.4.0 | cpe:2.3:a:f5:big-ip_local_traffic_manager:11.4.0:*:*:*:*:*:*:* |
| f5 | big-ip_local_traffic_manager | 11.4.1 | cpe:2.3:a:f5:big-ip_local_traffic_manager:11.4.1:*:*:*:*:*:*:* |
| f5 | big-ip_local_traffic_manager | 11.5.0 | cpe:2.3:a:f5:big-ip_local_traffic_manager:11.5.0:*:*:*:*:*:*:* |
| f5 | big-ip_local_traffic_manager | 11.5.1 | cpe:2.3:a:f5:big-ip_local_traffic_manager:11.5.1:*:*:*:*:*:*:* |
| f5 | big-ip_local_traffic_manager | 11.5.2 | cpe:2.3:a:f5:big-ip_local_traffic_manager:11.5.2:*:*:*:*:*:*:* |
| f5 | big-ip_local_traffic_manager | 11.5.3 | cpe:2.3:a:f5:big-ip_local_traffic_manager:11.5.3:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://www.securitytracker.com/id/1036709 | Third Party Advisory VDB Entry |
| http://www.securitytracker.com/id/1036710 | Third Party Advisory VDB Entry |
| https://support.f5.com/kb/en-us/solutions/public/k/06/sol06045217.html | Vendor Advisory |