CVE-2026-28758 Details
Description
When BIG-IP DNS is provisioned, a vulnerability exists in the gtm_add and bigip_add iControl REST commands that return the ssh-password parameter in cleartext in the iControl REST response and is also logged in the audit log. This may allow a highly privileged, authenticated attacker with access to the audit log to view sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
A vulnerability exists in the BIG-IP DNS iControl REST commands 'gtm_add' and 'bigip_add', which return the 'ssh-password' parameter in cleartext. This information is also logged in the audit log. As a result, a highly privileged, authenticated attacker with access to the audit log could view sensitive information. This issue affects BIG-IP DNS versions 17.5.0 to 17.5.1 and 17.1.0 to 17.1.3, as well as all 16.x versions. Note that versions that have reached End of Technical Support are not evaluated.
Users can upgrade to BIG-IP DNS versions 17.5.1.4 or 17.1.3.1 to address this vulnerability. For more information about managing BIG-IP product hotfixes, refer to the F5 article K13123.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://my.f5.com/manage/s/article/K000158070 | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-312 | Cleartext Storage of Sensitive Information | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| f5 big-ip domain name system | >= 16.1.0, <= 16.1.6 >= 17.1.0, < 17.1.3.1 >= 17.5.0, <= 17.5.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 29, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 13, 2026 | New CVE Received | [email protected] |