A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages
Impact:
An attacker may trick authenticated BIG-IP users
into accessing malicious links and reflect a spoofed error message in
the victim's BIG-IP Configuration utility web browser session. This is a
control plane issue; there is no data plane exposure.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
To mitigate this vulnerability, you may take the following actions:
When you have finished using the BIG-IP
Configuration utility, you should log off and close all instances of
your web browser. Do not use the same web browser that you use to manage
the BIG-IP Configuration utility for any other purposes, such as
browsing the internet. If you must perform both actions on the same
client machine, F5 recommends that you do so in separate browsers