On BIG-IP 11.5.1-11.5.8, 11.6.1-11.6.3, 12.1.0-12.1.3.6, 13.0.0-13.1.1.1, and 14.0.0-14.0.0.2, under certain conditions, hardware systems with a High-Speed Bridge and using non-default Layer 2 forwarding configurations may experience a lockup of the High-Speed Bridge.
Conclusion & alert: CVE-2019-6604 is rated Moderate Risk (48.1/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 1.02%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.65% | 1.02% | +0.37% |
| 2 | 2025-03-30 | 1.01% | 0.65% | -0.37% |
| 3 | 2025-03-29 | — | 1.01% | — |
Full EPSS history (9 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.8 | 3.0 | MEDIUM |
|
2.2 | 4.0 | [email protected] |
| 4.3 | 2.0 | MEDIUM |
|
8.6 | 2.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| f5 | big-ip_access_policy_manager | >= 11.2.1, <= 11.5.8 | cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_access_policy_manager | >= 11.6.0, <= 11.6.3 | cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_access_policy_manager | >= 12.1.0, <= 12.1.3 | cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_access_policy_manager | >= 13.0.0, <= 13.1.1 | cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_access_policy_manager | 14.0.0 | cpe:2.3:a:f5:big-ip_access_policy_manager:14.0.0:*:*:*:*:*:*:* |
| f5 | big-ip_advanced_firewall_manager | >= 11.2.1, <= 11.5.8 | cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_advanced_firewall_manager | >= 11.6.0, <= 11.6.3 | cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_advanced_firewall_manager | >= 12.1.0, <= 12.1.3 | cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_advanced_firewall_manager | >= 13.0.0, <= 13.1.1 | cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_advanced_firewall_manager | 14.0.0 | cpe:2.3:a:f5:big-ip_advanced_firewall_manager:14.0.0:*:*:*:*:*:*:* |
| f5 | big-ip_application_acceleration_manager | >= 11.2.1, <= 11.5.8 | cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_application_acceleration_manager | >= 11.6.0, <= 11.6.3 | cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_application_acceleration_manager | >= 12.1.0, <= 12.1.3 | cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_application_acceleration_manager | >= 13.0.0, <= 13.1.1 | cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_application_acceleration_manager | 14.0.0 | cpe:2.3:a:f5:big-ip_application_acceleration_manager:14.0.0:*:*:*:*:*:*:* |
| f5 | big-ip_edge_gateway | >= 11.2.1, <= 11.5.8 | cpe:2.3:a:f5:big-ip_edge_gateway:*:*:*:*:*:*:*:* |
| f5 | big-ip_edge_gateway | >= 11.6.0, <= 11.6.3 | cpe:2.3:a:f5:big-ip_edge_gateway:*:*:*:*:*:*:*:* |
| f5 | big-ip_edge_gateway | >= 12.1.0, <= 12.1.3 | cpe:2.3:a:f5:big-ip_edge_gateway:*:*:*:*:*:*:*:* |
| f5 | big-ip_edge_gateway | >= 13.0.0, <= 13.1.1 | cpe:2.3:a:f5:big-ip_edge_gateway:*:*:*:*:*:*:*:* |
| f5 | big-ip_edge_gateway | 14.0.0 | cpe:2.3:a:f5:big-ip_edge_gateway:14.0.0:*:*:*:*:*:*:* |
| f5 | big-ip_fraud_protection_service | >= 11.2.1, <= 11.5.8 | cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:* |
| f5 | big-ip_fraud_protection_service | >= 11.6.0, <= 11.6.3 | cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:* |
| f5 | big-ip_fraud_protection_service | >= 12.1.0, <= 12.1.3 | cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:* |
| f5 | big-ip_fraud_protection_service | >= 13.0.0, <= 13.1.1 | cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:* |
| f5 | big-ip_fraud_protection_service | 14.0.0 | cpe:2.3:a:f5:big-ip_fraud_protection_service:14.0.0:*:*:*:*:*:*:* |
| f5 | big-ip_global_traffic_manager | >= 11.2.1, <= 11.5.8 | cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_global_traffic_manager | >= 11.6.0, <= 11.6.3 | cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_global_traffic_manager | >= 12.1.0, <= 12.1.3 | cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_global_traffic_manager | >= 13.0.0, <= 13.1.1 | cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_global_traffic_manager | 14.0.0 | cpe:2.3:a:f5:big-ip_global_traffic_manager:14.0.0:*:*:*:*:*:*:* |
| f5 | big-ip_link_controller | >= 11.2.1, <= 11.5.8 | cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:* |
| f5 | big-ip_link_controller | >= 11.6.0, <= 11.6.3 | cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:* |
| f5 | big-ip_link_controller | >= 12.1.0, <= 12.1.3 | cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:* |
| f5 | big-ip_link_controller | >= 13.0.0, <= 13.1.1 | cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:* |
| f5 | big-ip_link_controller | 14.0.0 | cpe:2.3:a:f5:big-ip_link_controller:14.0.0:*:*:*:*:*:*:* |
| f5 | big-ip_local_traffic_manager | >= 11.2.1, <= 11.5.8 | cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_local_traffic_manager | >= 11.6.0, <= 11.6.3 | cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_local_traffic_manager | >= 12.1.0, <= 12.1.3 | cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_local_traffic_manager | >= 13.0.0, <= 13.1.1 | cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_local_traffic_manager | 14.0.0 | cpe:2.3:a:f5:big-ip_local_traffic_manager:14.0.0:*:*:*:*:*:*:* |
| f5 | big-ip_policy_enforcement_manager | >= 11.2.1, <= 11.5.8 | cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_policy_enforcement_manager | >= 11.6.0, <= 11.6.3 | cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_policy_enforcement_manager | >= 12.1.0, <= 12.1.3 | cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_policy_enforcement_manager | >= 13.0.0, <= 13.1.1 | cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_policy_enforcement_manager | 14.0.0 | cpe:2.3:a:f5:big-ip_policy_enforcement_manager:14.0.0:*:*:*:*:*:*:* |
| f5 | big-ip_protocol_security_module | >= 11.2.1, <= 11.5.8 | cpe:2.3:a:f5:big-ip_protocol_security_module:*:*:*:*:*:*:*:* |
| f5 | big-ip_protocol_security_manager | >= 11.6.0, <= 11.6.3 | cpe:2.3:h:f5:big-ip_protocol_security_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_protocol_security_manager | >= 12.1.0, <= 12.1.3 | cpe:2.3:h:f5:big-ip_protocol_security_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_protocol_security_manager | >= 13.0.0, <= 13.1.1 | cpe:2.3:h:f5:big-ip_protocol_security_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_protocol_security_manager | 14.0.0 | cpe:2.3:h:f5:big-ip_protocol_security_manager:14.0.0:*:*:*:*:*:*:* |
| f5 | big-ip_webaccelerator | <= 14.0.0 | cpe:2.3:a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:* |
| f5 | big-ip_webaccelerator | >= 11.2.1, <= 11.5.8 | cpe:2.3:a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:* |
| f5 | big-ip_webaccelerator | >= 11.6.0, <= 11.6.3 | cpe:2.3:a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:* |
| f5 | big-ip_webaccelerator | >= 12.0.0, <= 12.1.3 | cpe:2.3:a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:* |
| f5 | big-ip_webaccelerator | >= 13.0.0, <= 13.1.1 | cpe:2.3:a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:* |
| f5 | big-ip_analytics | >= 11.2.1, <= 11.5.8 | cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:* |
| f5 | big-ip_analytics | >= 11.6.0, <= 11.6.3 | cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:* |
| f5 | big-ip_analytics | >= 12.1.0, <= 12.1.3 | cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:* |
| f5 | big-ip_analytics | >= 13.0.0, <= 13.1.1 | cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:* |
| f5 | big-ip_analytics | 14.0.0 | cpe:2.3:a:f5:big-ip_analytics:14.0.0:*:*:*:*:*:*:* |
| f5 | big-ip_application_security_manager | >= 11.2.1, <= 11.5.8 | cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_application_security_manager | >= 11.6.0, <= 11.6.3 | cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_application_security_manager | >= 12.1.0, <= 12.1.3 | cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_application_security_manager | >= 13.0.0, <= 13.1.1 | cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:* |
| f5 | big-ip_application_security_manager | 14.0.0 | cpe:2.3:a:f5:big-ip_application_security_manager:14.0.0:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://support.f5.com/csp/article/K26455071 | Vendor Advisory |