Vulnerability index

Browse CVEs

865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Big Ip Access Policy Manager MEDIUM 6.5
CVE-2020-27724

In BIG-IP APM versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, on sy…

Fix: 13.1.3.5 / 14.1.3.1+
Fix from $1,600 2020-12-24
Nginx Controller CRITICAL 9.8
CVE-2020-27730

In versions 3.0.0-3.9.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller Agent does not use absolute paths when calling system utilities.

Fix: 3.10.0+
Fix from $2,300 2020-12-11
Big Ip Access Policy Manager CRITICAL 9.6
CVE-2020-5948

On BIG-IP versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.2.7, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, undisclosed endpoints in…

Fix: 13.1.3.5 / 14.1.2.8+
Fix from $2,300 2020-12-11
Big Ip Access Policy Manager HIGH 7.5
CVE-2020-5949

On BIG-IP versions 14.0.0-14.0.1 and 13.1.0-13.1.3.4, certain traffic pattern sent to a virtual server configured with an FTP profile can cause the F…

Fix: 13.1.3.5 / 14.1.0+
Fix from $1,950 2020-12-11
Big Ip Advanced Firewall Manager MEDIUM 5.3
CVE-2020-5950

On BIG-IP 14.1.0-14.1.2.6, undisclosed endpoints in iControl REST allow for a reflected XSS attack, which could lead to a complete compromise of the …

Fix: 14.1.2.7+
Fix from $1,600 2020-12-11
Big Ip Advanced Firewall Manager HIGH 7.5
CVE-2020-27713

In certain configurations on version 13.1.3.4, when a BIG-IP AFM HTTP security profile is applied to a virtual server and the BIG-IP system receives …

Mitigation only
Fix from $1,950 2020-12-11
Big Ip Access Policy Manager HIGH 8.4
CVE-2020-5945

In BIG-IP versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.2.7, undisclosed TMUI page contains a stored cross site scripting vulnerability …

Fix: 14.1.2.8 / 15.1.1+
Fix from $1,950 2020-11-05
Big Ip Access Policy Manager HIGH 7.5
CVE-2020-5939

In versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.3, 15.0.0-15.0.1.3, 14.1.0-14.1.2.6, and 13.1.0-13.1.3.4, BIG-IP Virtual Edition (VE) systems on VMware, w…

Fix: 14.1.2.7 / 15.1.0.4+
Fix from $1,950 2020-11-05
Big Ip Access Policy Manager HIGH 7.5
CVE-2020-5941

On BIG-IP versions 16.0.0-16.0.0.1 and 15.1.0-15.1.0.5, using the RESOLV::lookup command within an iRule may cause the Traffic Management Microkernel…

Fix: 15.1.1 / 16.0.1+
Fix from $1,950 2020-11-05
Big Ip Policy Enforcement Manager HIGH 7.5
CVE-2020-5942

In BIG-IP PEM versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.2.7, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, when processing Capa…

Fix: 14.1.2.8 / 15.1.1+
Fix from $1,950 2020-11-05
Big Ip Advanced Web Application Firewall HIGH 7.5
CVE-2020-5946

In BIG-IP Advanced WAF and FPS versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.2.7, under some circumstances, certain format client-side a…

Fix: 14.1.2.8 / 15.1.1+
Fix from $1,950 2020-11-05
Big Ip Access Policy Manager MEDIUM 6.5
CVE-2020-5943

In versions 14.1.0-14.1.0.1 and 14.1.2.5-14.1.2.7, when a BIG-IP object is created or listed through the REST interface, the protected fields are obf…

Fix: after 14.1.2.7
Fix from $1,600 2020-11-05
Big Ip Access Policy Manager MEDIUM 5.4
CVE-2020-5940

In versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.2.3, a stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of…

Fix: 14.1.2.4 / 15.1.1+
Fix from $1,600 2020-11-05
Big Ip Access Policy Manager HIGH 7.5
CVE-2020-5931

On BIG-IP 15.1.0-15.1.0.5, 14.1.0-14.1.2.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, Virtual servers with a OneConnect profile may inco…

Fix: 14.1.2.5 / 15.1.1+
Fix from $1,950 2020-10-29
Big Ip Access Policy Manager HIGH 7.5
CVE-2020-5933

On versions 15.1.0-15.1.0.5, 14.1.0-14.1.2.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, when a BIG-IP system that has a virtual server c…

Fix: 11.6.5.2 / 12.1.5.2+
Fix from $1,950 2020-10-29
Big Ip Local Traffic Manager HIGH 7.5
CVE-2020-5936

On BIG-IP LTM 15.1.0-15.1.0.5, 14.1.0-14.1.2.7, 13.1.0-13.1.3.4, and 12.1.0-12.1.5.1, the Traffic Management Microkernel (TMM) process may consume ex…

Fix: 12.1.5.2 / 14.1.2.8+
Fix from $1,950 2020-10-29
Big Ip Access Policy Manager MEDIUM 6.5
CVE-2020-5934

On BIG-IP APM 15.1.0-15.1.0.5, 14.1.0-14.1.2.3, and 13.1.0-13.1.3.3, when multiple HTTP requests from the same client to configured SAML Single Logou…

Fix: 13.1.3.4 / 14.1.2.4+
Fix from $1,600 2020-10-29
Big Ip Access Policy Manager MEDIUM 5.9
CVE-2020-5935

On BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, FPS, GTM, Link Controller, PEM) versions 15.1.0-15.1.0.5, 14.1.0-14.1.2.3, and 13.1.0-13.1.3.3, w…

Fix: 13.1.3.4 / 14.1.2.4+
Fix from $1,600 2020-10-29
Big Ip Advanced Firewall Manager HIGH 7.5
CVE-2020-5937

On BIG-IP AFM 15.1.0-15.1.0.5, the Traffic Management Microkernel (TMM) may produce a core file while processing layer 4 (L4) behavioral denial-of-se…

Fix: 15.1.1+
Fix from $1,950 2020-10-29
Big Ip Access Policy Manager MEDIUM 6.5
CVE-2020-5938

On BIG-IP 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, when negotiating IPSec tunnels with configured, authenticated peers, the peer may ne…

Fix: after 13.1.3.4
Fix from $1,600 2020-10-29
Big Ip Access Policy Manager HIGH 7.5
CVE-2020-5930

In BIG-IP 15.0.0-15.1.0.4, 14.1.0-14.1.2.7, 13.1.0-13.1.3.3, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2 and BIG-IQ 5.2.0-7.1.0, unauthenticated attackers c…

Fix: 13.1.3.4 / 14.1.2.8+
Fix from $1,950 2020-09-25
Big Ip Access Policy Manager MEDIUM 5.9
CVE-2020-5929

In versions 13.0.0-13.0.0 HF2, 12.1.0-12.1.2 HF1, and 11.6.1-11.6.2, BIG-IP platforms with Cavium Nitrox SSL hardware acceleration cards, a Virtual S…

Fix: 11.6.2 / 12.1.2+
Fix from $1,600 2020-09-25
Big Ip Access Policy Manager HIGH 7.5
CVE-2020-5921

in BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.6, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2, Syn flood causes large n…

Fix: 12.1.5.2 / 14.1.2.7+
Fix from $1,950 2020-08-26
Big Ip Access Policy Manager HIGH 7.5
CVE-2020-5925

In BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.6, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, undisclosed internally g…

Fix: 11.6.5.2 / 12.1.5.2+
Fix from $1,950 2020-08-26
Big Ip Access Policy Manager HIGH 7.5
CVE-2020-5926

In BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, and 14.1.0-14.1.2.6, a BIG-IP virtual server with a Session Initiation Protocol (SIP) ALG profil…

Fix: 14.1.2.7 / 15.0.1.4+
Fix from $1,950 2020-08-26
Big Ip Application Security Manager MEDIUM 6.1
CVE-2020-5927

In versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, and 14.1.0-14.1.2.6, BIG-IP ASM Configuration utility Stored-Cross Site Scripting.

Fix: 14.1.2.7 / 15.0.1.4+
Fix from $1,600 2020-08-26
Big Ip Access Policy Manager HIGH 8.8
CVE-2020-5922

In BIG-IP versions 15.0.0-15.1.0.4, 14.1.0-14.1.2.6, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2, iControl REST does not implement Cross Si…

Fix: 12.1.5.2 / 13.1.3.4+
Fix from $1,950 2020-08-26
Big Ip Application Security Manager HIGH 7.5
CVE-2020-5914

In BIG-IP ASM versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, undisclosed server c…

Fix: 11.6.5.2 / 12.1.5.2+
Fix from $1,950 2020-08-26
Big Ip Access Policy Manager HIGH 7.5
CVE-2020-5918

In BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management M…

Fix: 11.6.5.2 / 12.1.5.2+
Fix from $1,950 2020-08-26
Big Ip Access Policy Manager HIGH 7.5
CVE-2020-5919

In versions 15.1.0-15.1.0.4, rendering of certain session variables by BIG-IP APM UI-based agents in an access profile configured with Modern customi…

Fix: 15.1.0.5+
Fix from $1,950 2020-08-26