Vulnerability index

Browse CVEs

865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Big Ip Access Policy Manager HIGH 8.8
CVE-2021-23026

BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x and 11.6.x an…

Fix: after 16.0.1.1
Fix from $1,950 2021-09-14
Big Ip Access Policy Manager MEDIUM 6.1
CVE-2021-23027

On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, and 14.1.x before 14.1.4.3, a DOM based cross-site scripting (XSS) vulnerability exists in…

Fix: after 16.0.1.1
Fix from $1,600 2021-09-14
Big Ip Access Policy Manager HIGH 8.8
CVE-2021-23025

On version 15.1.x before 15.1.0.5, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.5, and all versions of 12.1.x and 11.6.x, an authenticated remote com…

Fix: 13.1.3.5 / 14.1.3.1+
Fix from $1,950 2021-09-14
Big Ip Advanced Web Application Firewall HIGH 7.5
CVE-2021-23028

On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, and 13.1.x before 13.1.4, when JSON content profiles are configure…

Fix: 15.1.3.1+
Fix from $1,950 2021-09-14
Big Ip Advanced Web Application Firewall HIGH 7.5
CVE-2021-23030

On BIG-IP Advanced WAF and BIG-IP ASM version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, 13.1.x before 13.1.4.1, and all…

Fix: after 16.0.1.1
Fix from $1,950 2021-09-14
Big Ip Advanced Web Application Firewall CRITICAL 9.9
CVE-2021-23031

On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.1, 13.1.x before 13.1.4, 12.1.x before 12.1.6, and 11.6.x before 11.6.5…

Fix: after 16.0.1.1
Fix from $2,300 2021-09-14
Big Ip Advanced Web Application Firewall HIGH 7.5
CVE-2021-23036

On version 16.0.x before 16.0.1.2, when a BIG-IP ASM and DataSafe profile are configured on a virtual server, undisclosed requests can cause the Traf…

Fix: after 16.0.1
Fix from $1,950 2021-09-14
Big Ip Access Policy Manager CRITICAL 9.6
CVE-2021-23037

On all versions of 16.1.x, 16.0.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x, a reflected cross-site scripting (XSS) vulnerability exists in an undi…

Fix: after 16.1.0
Fix from $2,300 2021-09-14
Big Ip Access Policy Manager CRITICAL 9.0
CVE-2021-23038

On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x, a stored cross…

Fix: 13.1.4.1 / 14.1.4.2+
Fix from $2,300 2021-09-14
Big Ip Domain Name System HIGH 7.5
CVE-2021-23032

On version 16.x before 16.1.0, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x and 12.1.x, when a BIG-IP DNS system is con…

Fix: 14.1.4.4 / 15.1.3.1+
Fix from $1,950 2021-09-14
Big Ip Advanced Web Application Firewall HIGH 7.5
CVE-2021-23033

On BIG-IP Advanced WAF and BIG-IP ASM version 16.x before 16.1.0x, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, 13.1.x before 13.1.4.1, and all ve…

Fix: 13.1.4.1 / 14.1.4.3+
Fix from $1,950 2021-09-14
Big Ip Access Policy Manager HIGH 7.5
CVE-2021-23034

On BIG-IP version 16.x before 16.1.0 and 15.1.x before 15.1.3.1, when a DNS profile using a DNS cache resolver is configured on a virtual server, und…

Fix: 15.1.3.1 / 16.1.0+
Fix from $1,950 2021-09-14
Big Ip Access Policy Manager HIGH 7.5
CVE-2021-23035

On BIG-IP 14.1.x before 14.1.4.4, when an HTTP profile is configured on a virtual server, after a specific sequence of packets, chunked responses can…

Fix: after 14.1.4.4
Fix from $1,950 2021-09-14
Big Ip Access Policy Manager HIGH 7.5
CVE-2021-23039

On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.2.8, and all versions of 13.1.x and 12.1.x, when IPSec is configured on a…

Fix: 14.1.2.8 / 15.1.3+
Fix from $1,950 2021-09-14
Big Ip Access Policy Manager HIGH 7.5
CVE-2021-23045

On BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, 13.1.x before 13.1.4.1, and all versions of 12.1.x, when an…

Fix: 13.1.4.1 / 14.1.4.3+
Fix from $1,950 2021-09-14
Big Ip Access Policy Manager HIGH 7.5
CVE-2021-23044

On BIG-IP version 16.x before 16.1.0, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x and 11.6.x, …

Fix: 13.1.4.1 / 14.1.4.2+
Fix from $1,950 2021-09-14
Big Ip Access Policy Manager HIGH 7.5
CVE-2021-23042

On BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before 13.1.4, and 12.1.x before 12.1.6, when an HTTP pr…

Fix: 12.1.6 / 13.1.4+
Fix from $1,950 2021-09-14
Big Ip Access Policy Manager MEDIUM 6.5
CVE-2021-23043

On BIG-IP, on all versions of 16.1.x, 16.0.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x, a directory traversal vulnerability exists in an undisclose…

Fix: after 16.1.0
Fix from $1,600 2021-09-14
Big Ip Advanced Firewall Manager HIGH 8.8
CVE-2021-23040

On BIG-IP AFM version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x, a SQL…

Fix: 13.1.4.1 / 14.1.4.2+
Fix from $1,950 2021-09-14
Big Ip Access Policy Manager MEDIUM 6.1
CVE-2021-23041

On BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x, a DOM bas…

Fix: 13.1.4.1 / 14.1.4.2+
Fix from $1,600 2021-09-14
Big Ip Access Policy Manager MEDIUM 5.3
CVE-2021-23047

On version 16.x before 16.1.0, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, and all versions of 13.1.x, 12.1.x and 11.6.x, when BIG-IP APM perform…

Fix: 13.1.4 / 14.1.4.3+
Fix from $1,600 2021-09-14
Big Ip Access Policy Manager HIGH 7.5
CVE-2021-23049

On BIG-IP version 16.0.x before 16.0.1.2 and 15.1.x before 15.1.3, when the iRules RESOLVER::summarize command is used on a virtual server, undisclos…

Fix: 15.1.3 / 16.0.1.2+
Fix from $1,950 2021-09-14
Big Ip Advanced Web Application Firewall HIGH 7.5
CVE-2021-23050

On BIG-IP Advanced WAF and BIG-IP ASM version 16.0.x before 16.0.1.2 and 15.1.x before 15.1.3 and NGINX App Protect on all versions before 3.5.0, whe…

Fix: 3.5.0 / 15.1.3.1+
Fix from $1,950 2021-09-14
Big Ip Access Policy Manager HIGH 7.5
CVE-2021-23051

On BIG-IP versions 15.1.0.4 through 15.1.3, when the Data Plane Development Kit (DPDK)/Elastic Network Adapter (ENA) driver is used with BIG-IP on Am…

Fix: 15.1.3.1+
Fix from $1,950 2021-09-14
Big Ip Access Policy Manager MEDIUM 6.1
CVE-2021-23052

On version 14.1.x before 14.1.4.4 and all versions of 13.1.x, an open redirect vulnerability exists on virtual servers enabled with a BIG-IP APM acce…

Fix: 14.1.4.4+
Fix from $1,600 2021-09-14
Big Ip Advanced Web Application Firewall MEDIUM 5.3
CVE-2021-23053

On version 15.1.x before 15.1.3, 14.1.x before 14.1.3.1, and 13.1.x before 13.1.3.6, when the brute force protection feature of BIG-IP Advanced WAF o…

Fix: 13.1.3.6 / 14.1.3.1+
Fix from $1,600 2021-09-14
Big Ip Access Policy Manager HIGH 7.5
CVE-2021-23048

On BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, 13.1.x before 13.1.4.1, and all versions of 12.1.x and 11.6…

Fix: 13.1.4.1 / 14.1.4.3+
Fix from $1,950 2021-09-14
Big Ip Access Policy Manager HIGH 7.8
CVE-2021-23022

On version 7.2.1.x before 7.2.1.3 and 7.1.x before 7.1.9.9 Update 1, the BIG-IP Edge Client Windows Installer Service's temporary folder has weak fil…

Fix: 7.2.1.3+
Fix from $1,950 2021-06-10
Big Ip Access Policy Manager HIGH 7.8
CVE-2021-23023

On version 7.2.1.x before 7.2.1.3 and 7.1.x before 7.1.9.9 Update 1, a DLL hijacking issue exists in cachecleaner.dll included in the BIG-IP Edge Cli…

Fix: 7.2.1.3+
Fix from $1,950 2021-06-10
Big Iq Centralized Management HIGH 7.2
CVE-2021-23024EPSS 5%

On version 8.0.x before 8.0.0.1, and all 6.x and 7.x versions, the BIG-IQ Configuration utility has an authenticated remote command execution vulnera…

Fix: 8.0.0.1+
Fix from $1,950 2021-06-10