CVE-2016-5745
Summary
| CVE | CVE-2016-5745 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-10-05 16:59:03 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | F5 BIG-IP LTM systems 11.x before 11.2.1 HF16, 11.3.x, 11.4.x before 11.4.1 HF11, 11.5.0, 11.5.1 before HF11, 11.5.2, 11.5.3, 11.5.4 before HF2, 11.6.0 before HF8, 11.6.1 before HF1, 12.0.0 before HF4, and 12.1.0 before HF2 allow remote attackers to modify or extract system configuration files via vectors involving NAT64. |
Risk And Classification
Primary CVSS: v3.0 9.8 CRITICAL from [email protected]
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.038880000 probability, percentile 0.883220000 (date 2026-05-07)
Problem Types: CWE-284 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 9.8 | CRITICAL | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 10 | AV:N/AC:L/Au:N/C:C/I:C/A:C |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | F5 | Big-ip Local Traffic Manager | 11.0.0 | All | All | All |
| Application | F5 | Big-ip Local Traffic Manager | 11.1.0 | All | All | All |
| Application | F5 | Big-ip Local Traffic Manager | 11.2.0 | All | All | All |
| Application | F5 | Big-ip Local Traffic Manager | 11.2.1 | All | All | All |
| Application | F5 | Big-ip Local Traffic Manager | 11.3.0 | All | All | All |
| Application | F5 | Big-ip Local Traffic Manager | 11.4.0 | All | All | All |
| Application | F5 | Big-ip Local Traffic Manager | 11.4.1 | All | All | All |
| Application | F5 | Big-ip Local Traffic Manager | 11.5.0 | All | All | All |
| Application | F5 | Big-ip Local Traffic Manager | 11.5.1 | All | All | All |
| Application | F5 | Big-ip Local Traffic Manager | 11.5.2 | All | All | All |
| Application | F5 | Big-ip Local Traffic Manager | 11.5.3 | All | All | All |
| Application | F5 | Big-ip Local Traffic Manager | 11.5.4 | All | All | All |
| Application | F5 | Big-ip Local Traffic Manager | 11.6.0 | All | All | All |
| Application | F5 | Big-ip Local Traffic Manager | 11.6.1 | All | All | All |
| Application | F5 | Big-ip Local Traffic Manager | 12.0.0 | All | All | All |
| Application | F5 | Big-ip Local Traffic Manager | 12.1.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SOL64743453 - NAT64 vulnerability CVE-2016-5745 | af854a3a-2127-422b-91ae-364da2661108 | support.f5.com | Vendor Advisory |
| F5 BIG-IP LTM Unspecified CGNAT/NAT64 Flaw Lets Remote Users Modify the Configuration - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| F5 BIG-IP LTM Products CVE-2016-5745 Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.