Vulnerability index

Browse CVEs

865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Nginx CRITICAL 9.8
CVE-2017-20005

NGINX before 1.13.6 has a buffer overflow for years that exceed four digits, as demonstrated by a file with a modification date in 1969 that causes a…

Fix: 1.13.6+
Fix from $2,300 2021-06-06
Nginx Controller MEDIUM 5.5
CVE-2021-23021

The Nginx Controller 3.x before 3.7.0 agent configuration file /etc/controller-agent/agent.conf is world readable with current permission bits set to…

Fix: 3.7.0+
Fix from $1,600 2021-06-01
Nginx Controller HIGH 7.8
CVE-2021-23019

The NGINX Controller 2.0.0 thru 2.9.0 and 3.x before 3.15.0 Administrator password may be exposed in the systemd.txt file that is included in the NGI…

Fix: 3.15.0+
Fix from $1,950 2021-06-01
Nginx HIGH 7.7
CVE-2021-23017EPSS 53%

A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte…

Fix: 1.19.3.2 / 1.20.1+
Fix from $1,950 2021-06-01
Nginx Controller MEDIUM 5.5
CVE-2021-23020

The NAAS 3.x before 3.10.0 API keys were generated using an insecure pseudo-random string and hashing algorithm which could lead to predictable keys.

Fix: 3.10.0+
Fix from $1,600 2021-06-01
Nginx Controller HIGH 7.4
CVE-2021-23018

Intra-cluster communication does not use TLS. The services within the NGINX Controller 3.x before 3.4.0 namespace are using cleartext protocols insid…

Fix: after 3.4.0
Fix from $1,950 2021-06-01
Big Ip Advanced Web Application Firewall HIGH 8.8
CVE-2021-23014

On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, and 14.1.x before 14.1.4, BIG-IP Advanced WAF and ASM are missing authorization checks for …

Fix: 14.1.4 / 15.1.3+
Fix from $1,950 2021-05-10
Big Ip Access Policy Manager HIGH 8.2
CVE-2021-23012

On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, and 13.1.x before 13.1.4, lack of input validation for items u…

Fix: 13.1.4 / 14.1.4+
Fix from $1,950 2021-05-10
Big Ip Access Policy Manager HIGH 7.5
CVE-2021-23009

On BIG-IP version 16.0.x before 16.0.1.1 and 15.1.x before 15.1.3, malformed HTTP/2 requests may cause an infinite loop which causes a Denial of Serv…

Fix: 15.1.3 / 16.0.1.1+
Fix from $1,950 2021-05-10
Big Ip Application Security Manager HIGH 7.5
CVE-2021-23010

On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.5, and 12.1.x before 12.1.5.3, when the BIG-IP…

Fix: after 16.0.1.1
Fix from $1,950 2021-05-10
Big Ip Access Policy Manager HIGH 7.2
CVE-2021-23015

On BIG-IP 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.0.8 through 13.1.3.6, and all versions of 16.0.x, when running in Appliance Mode, an aut…

Fix: 13.1.4 / 14.1.4+
Fix from $1,950 2021-05-10
Big Ip Access Policy Manager MEDIUM 5.3
CVE-2021-23016

On BIG-IP APM versions 15.1.x before 15.1.3, 14.1.x before 14.1.4.1, 13.1.x before 13.1.4, and all versions of 16.0.x, 12.1.x, and 11.6.x, an attacke…

Fix: 13.1.4 / 14.1.4.1+
Fix from $1,600 2021-05-10
Big Ip Access Policy Manager CRITICAL 9.8
CVE-2021-23008

On version 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before 13.1.4, 12.1.x before 12.1.6, and all versions of 16.0.x and 11.6.x., BIG-IP APM…

Fix: 11.6.5 / 12.1.5+
Fix from $2,300 2021-05-10
Big Ip Access Policy Manager HIGH 7.5
CVE-2021-23011

On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before 13.1.4, 12.1.x before 12.1.6, and 11.6.x before 11.6.5.…

Fix: 11.6.5.3 / 12.1.6+
Fix from $1,950 2021-05-10
Big Ip Access Policy Manager HIGH 7.5
CVE-2021-23013

On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, the Traffi…

Fix: 12.1.5.3 / 13.1.4+
Fix from $1,950 2021-05-10
Big Iq Centralized Management CRITICAL 9.1
CVE-2021-23005

On all 7.x and 6.x versions (fixed in 8.0.0), when using a Quorum device for BIG-IQ high availability (HA) for automatic failover, BIG-IQ does not ma…

Fix: 8.0.0+
Fix from $2,300 2021-03-31
Big Iq Centralized Management HIGH 7.5
CVE-2021-22997

On all 7.x and 6.x versions (fixed in 8.0.0), BIG-IQ HA ElasticSearch service does not implement any form of authentication for the clustering transp…

Fix: 8.0.0+
Fix from $1,950 2021-03-31
Big Ip Access Policy Manager HIGH 7.5
CVE-2021-22999

On versions 15.0.x before 15.1.0 and 14.1.x before 14.1.4, the BIG-IP system provides an option to connect HTTP/2 clients to HTTP/1.x servers. When a…

Fix: 14.1.4 / 15.1.0+
Fix from $1,950 2021-03-31
Big Ip Access Policy Manager HIGH 7.5
CVE-2021-23000

On BIG-IP versions 13.1.3.4-13.1.3.6 and 12.1.5.2, if the tmm.http.rfc.enforcement BigDB key is enabled in a BIG-IP system, or the Bad host header va…

Fix: 13.1.3.6+
Fix from $1,950 2021-03-31
Big Ip Access Policy Manager HIGH 7.5
CVE-2021-23003

On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x b…

Fix: 11.6.5.3 / 12.1.5.3+
Fix from $1,950 2021-03-31
Big Ip Access Policy Manager HIGH 7.5
CVE-2021-23004

On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x b…

Fix: 11.6.5.3 / 12.1.5.3+
Fix from $1,950 2021-03-31
Big Iq Centralized Management MEDIUM 6.1
CVE-2021-23006

On all 7.x and 6.x versions (fixed in 8.0.0), undisclosed BIG-IQ pages have a reflected cross-site scripting vulnerability. Note: Software versions w…

Fix: 8.0.0+
Fix from $1,600 2021-03-31
Big Ip Access Policy Manager MEDIUM 5.3
CVE-2021-22998

On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x b…

Fix: 11.6.5.3 / 12.1.5.3+
Fix from $1,600 2021-03-31
Big Ip Access Policy Manager MEDIUM 5.3
CVE-2021-23007

On BIG-IP versions 14.1.4 and 16.0.1.1, when the Traffic Management Microkernel (TMM) process handles certain undisclosed traffic, it may start dropp…

Patch available
Fix from $1,600 2021-03-31
Big Ip Access Policy Manager CRITICAL 9.8
CVE-2021-22991 KEVEPSS 61%

On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, undisclo…

Fix: 12.1.5.3 / 13.1.3.6+
Fix from $2,300 2021-03-31
Big Ip Advanced Web Application Firewall HIGH 8.8
CVE-2021-22993

On BIG-IP Advanced WAF and BIG-IP ASM versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.6, and 12.1…

Fix: 12.1.5.3 / 13.1.3.6+
Fix from $1,950 2021-03-31
Big Iq Centralized Management HIGH 7.5
CVE-2021-22996

On all 7.x versions (fixed in 8.0.0), when set up for auto failover, a BIG-IQ Data Collection Device (DCD) cluster member that receives an undisclose…

Fix: 8.0.0+
Fix from $1,950 2021-03-31
Big Ip Access Policy Manager MEDIUM 6.1
CVE-2021-22994

On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x b…

Fix: 11.6.5.3 / 12.1.5.3+
Fix from $1,600 2021-03-31
Big Ip Access Policy Manager CRITICAL 9.8
CVE-2021-22992EPSS 73%

On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x b…

Fix: 11.6.5.3 / 12.1.5.3+
Fix from $2,300 2021-03-31
Big Iq Centralized Management HIGH 7.5
CVE-2021-22995

On all 7.x and 6.x versions (fixed in 8.0.0), BIG-IQ high availability (HA) when using a Quorum device for automatic failover does not implement any …

Fix: after 7.1.0
Fix from $1,950 2021-03-31