CVE-2014-5209: F5 BIG-IP Access Policy Manager

Medium severity, CVSS 5.3. EPSS: 2.5% chance of exploitation in the next 30 days.

An Information Disclosure vulnerability exists in NTP 4.2.7p25 private (mode 6/7) messages via a GET_RESTRICT control message, which could let a malicious user obtain sensitive information.

Affected products

  • F5 BIG-IP Access Policy Manager: from 10.2.1, up to and including 10.2.4; from 11.4.0, up to and including 11.6.4; from 12.0.0, up to and including 12.1.4; from 13.0.0, up to and including 13.1.1; from 14.0.0, up to and including 14.1.0; version 11.2.1 only; …
  • F5 BIG-IP Advanced Firewall Manager: from 11.4.0, up to and including 11.6.4; from 12.0.0, up to and including 12.1.4; from 13.0.0, up to and including 13.1.1; from 14.0.0, up to and including 14.1.0; version 15.0.0 only
  • F5 BIG-IP Analytics: from 11.4.0, up to and including 11.6.4; from 12.0.0, up to and including 12.1.4; from 13.0.0, up to and including 13.1.1; from 14.0.0, up to and including 14.1.0; version 11.2.1 only; version 15.0.0 only
  • F5 BIG-IP Application Acceleration Manager: from 11.4.0, up to and including 11.6.4; from 12.0.0, up to and including 12.1.4; from 13.0.0, up to and including 13.1.1; from 14.0.0, up to and including 14.1.0; version 15.0.0 only
  • F5 BIG-IP Application Security Manager: from 10.2.1, up to and including 10.2.4; from 11.4.0, up to and including 11.6.4; from 12.0.0, up to and including 12.1.4; from 13.0.0, up to and including 13.1.1; from 14.0.0, up to and including 14.1.0; version 11.2.1 only; …
  • F5 BIG-IP Domain Name System: from 12.0.0, up to and including 12.1.4; from 13.0.0, up to and including 13.1.1; from 14.0.0, up to and including 14.1.0; version 15.0.0 only
  • F5 BIG-IP Edge Gateway: from 10.2.1, up to and including 10.2.4; version 11.2.1 only
  • F5 BIG-IP Global Traffic Manager: from 10.2.1, up to and including 10.2.4; from 11.4.0, up to and including 11.6.4; version 11.2.1 only
  • F5 BIG-IP Link Controller: from 10.2.1, up to and including 10.2.4; from 11.4.0, up to and including 11.6.4; from 12.0.0, up to and including 12.1.4; from 13.0.0, up to and including 13.1.1; from 14.0.0, up to and including 14.1.0; version 11.2.1 only; …
  • F5 BIG-IP Local Traffic Manager: from 10.2.1, up to and including 10.2.4; from 11.4.0, up to and including 11.6.4; from 12.0.0, up to and including 12.1.4; from 13.0.0, up to and including 13.1.1; from 14.0.0, up to and including 14.1.0; version 11.2.1 only; …
  • F5 BIG-IP Policy Enforcement Manager: from 11.4.0, up to and including 11.6.4; from 12.0.0, up to and including 12.1.4; from 13.0.0, up to and including 13.1.1; from 14.0.0, up to and including 14.1.0; version 15.0.0 only
  • F5 BIG-IP Protocol Security Module: from 10.2.1, up to and including 10.2.4; from 11.4.0, up to and including 11.4.1
  • F5 BIG-IP WAN Optimization Manager: from 10.2.1, up to and including 10.2.4; version 11.2.1 only
  • F5 BIG-IP Webaccelerator: from 10.2.1, up to and including 10.2.4; version 11.2.1 only
  • F5 BIG-IQ ADC: version 4.5.0 only
  • F5 BIG-IQ Centralized Management: from 5.0.0, up to and including 5.4.0; from 6.0.0, up to and including 6.1.0; version 4.6.0 only
  • F5 BIG-IQ Cloud: from 4.0.0, up to and including 4.5.0
  • F5 BIG-IQ Cloud And Orchestration: version 1.0.0 only
  • F5 BIG-IQ Device: from 4.2.0, up to and including 4.5.0
  • F5 BIG-IQ Security: from 4.0.0, up to and including 4.5.0
  • F5 Enterprise Manager: version 3.1.1 only
  • F5 Iworkflow: from 2.0.0, up to and including 2.3.0
  • F5 Mobilesafe: version 1.0.0 only
  • F5 Websafe: version 1.0.0 only
  • Ntp Ntp: version 4.2.7 only

Published 2020-01-08. Last modified 2026-06-17.