CVE-2017-6130: F5 SSL Intercept Iapp

High severity, CVSS 7.4. EPSS: 1.1% chance of exploitation in the next 30 days.

F5 SSL Intercept iApp 1.5.0 - 1.5.7 and SSL Orchestrator 2.0 is vulnerable to a Server-Side Request Forgery (SSRF) attack when deployed using the Dynamic Domain Bypass (DDB) feature feature plus SNAT Auto Map option for egress traffic.

Affected products

  • F5 SSL Intercept Iapp: version 1.5.0 only; version 1.5.7 only
  • F5 SSL Orchestrator: version 2.0 only

Published 2017-04-06. Last modified 2026-06-17.