CVE-2013-3587: F5 Arx

Medium severity, CVSS 5.9. EPSS: 6% chance of exploitation in the next 30 days.

The HTTPS protocol, as used in unspecified web applications, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which makes it easier for man-in-the-middle attackers to obtain plaintext secret values by observing length differences during a series of guesses in which a string in an HTTP request URL potentially matches an unknown string in an HTTP response body, aka a "BREACH" attack, a different issue than CVE-2012-4929.

Affected products

  • F5 Arx: from 5.0.0, up to and including 5.3.1; from 6.0.0, up to and including 6.4.0
  • F5 BIG-IP Access Policy Manager: from 10.1.0, up to and including 10.2.4; from 11.0.0, up to and including 11.6.1; from 12.0.0, up to and including 12.1.2; version 13.0.0 only
  • F5 BIG-IP Advanced Firewall Manager: from 11.3.0, up to and including 11.6.1; from 12.0.0, up to and including 12.1.2; version 13.0.0 only
  • F5 BIG-IP Analytics: from 11.0.0, up to and including 11.6.1; from 12.0.0, up to and including 12.1.2; version 13.0.0 only
  • F5 BIG-IP Application Acceleration Manager: from 11.4.0, up to and including 11.6.1; from 12.0.0, up to and including 12.1.2; version 13.0.0 only
  • F5 BIG-IP Application Security Manager: from 9.2.0, up to and including 9.4.8; from 10.0.0, up to and including 10.2.4; from 11.0.0, up to and including 11.6.1; from 12.0.0, up to and including 12.1.2; version 13.0.0 only
  • F5 BIG-IP Edge Gateway: from 10.1.0, up to and including 10.2.4; from 11.0.0, up to and including 11.3.0
  • F5 BIG-IP Link Controller: from 9.2.2, up to and including 9.4.8; from 10.0.0, up to and including 10.2.4; from 11.0.0, up to and including 11.6.1; from 12.0.0, up to and including 12.1.2; version 13.0.0 only
  • F5 BIG-IP Local Traffic Manager: from 9.0.0, up to and including 9.6.1; from 10.0.0, up to and including 10.2.4; from 11.0.0, up to and including 11.6.1; from 12.0.0, up to and including 12.1.2; version 13.0.0 only
  • F5 BIG-IP Policy Enforcement Manager: from 11.3.0, up to and including 11.6.1; from 12.0.0, up to and including 12.1.2; version 13.0.0 only
  • F5 BIG-IP Protocol Security Module: from 9.4.5, up to and including 9.4.8; from 10.0.0, up to and including 10.2.4; from 11.0.0, up to and including 11.4.1
  • F5 BIG-IP WAN Optimization Manager: from 10.0.0, up to and including 10.2.4; from 11.0.0, up to and including 11.3.0
  • F5 BIG-IP Webaccelerator: from 9.4.0, up to and including 9.4.8; from 10.0.0, up to and including 10.2.4; from 11.0.0, up to and including 11.3.0
  • F5 Firepass: from 6.0.0, up to and including 6.1.0; version 7.0.0 only

Published 2020-02-21. Last modified 2026-06-16.