Last Modified: Jul 28, 2026
Affected Product(s):
BIG-IP ASM
Fixed In:
21.1.0.1, 17.5.1.8, 17.1.3.4
Opened: Jul 08, 2026 Severity: 3-Major
False positive with BruteForce in a certain configuration
- This can only happen with a release that has the fix for ID2296473 - Blocking is enabled with "Brute Force: Maximum login attempts are exceeded" - Mitigation Action" is set to "Alarm" for the detection object, such as "username - Detect Credential Stuffing" is enabled
Blocking is enabled for the "Brute Force: Maximum login attempts are exceeded" policy level, but only an alarm is set at the detection object level, such as "username". For the detection object, the request should not be blocked and should alarm only; however, it is blocked
None
None