Vulnerability index

Browse CVEs

865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Big Ip Local Traffic Manager HIGH 8.1
CVE-2020-5888

On versions 15.1.0-15.1.0.1, 15.0.0-15.0.1.2, and 14.1.0-14.1.2.3, BIG-IP Virtual Edition (VE) may expose a mechanism for adjacent network (layer 2) …

Fix: 14.1.2.4 / 15.0.1.3+
Fix from $1,950 2020-04-30
Big Ip Access Policy Manager CRITICAL 9.1
CVE-2020-5884

On versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.4, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the default deployment mode for BIG-IP high avai…

Fix: after 15.1.0.3
Fix from $2,300 2020-04-30
Big Ip Access Policy Manager CRITICAL 9.1
CVE-2020-5885

On versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, and 12.1.0-12.1.5.1, BIG-IP systems set up for connection mirroring in a high availabi…

Fix: after 15.1.0.1
Fix from $2,300 2020-04-30
Big Ip Access Policy Manager CRITICAL 9.1
CVE-2020-5886

On versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, and 12.1.0-12.1.5.1, BIG-IP systems setup for connection mirroring in a High Availabil…

Fix: after 15.1.0.1
Fix from $2,300 2020-04-30
Big Ip Access Policy Manager CRITICAL 9.1
CVE-2020-5887

On versions 15.1.0-15.1.0.1, 15.0.0-15.0.1.2, and 14.1.0-14.1.2.3, BIG-IP Virtual Edition (VE) may expose a mechanism for remote attackers to access …

Fix: after 15.1.0.1
Fix from $2,300 2020-04-30
Big Ip Access Policy Manager HIGH 7.5
CVE-2020-5882

On BIG-IP 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5, and 11.6.1-11.6.5.1, under certain conditions, the Intel QuickAssist Tech…

Fix: after 15.0.1.3
Fix from $1,950 2020-04-30
Big Ip Access Policy Manager HIGH 7.5
CVE-2020-5883

On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2.3, 14.0.0-14.0.1, and 13.1.0-13.1.3.1, when a virtual server is configured with HTTP explicit proxy and has an…

Fix: after 15.0.1.3
Fix from $1,950 2020-04-30
Big Ip Access Policy Manager HIGH 7.5
CVE-2020-5891

On BIG-IP 15.1.0-15.1.0.1, 15.0.0-15.0.1.2, and 14.1.0-14.1.2.3, undisclosed HTTP/2 requests can lead to a denial of service when sent to a virtual s…

Fix: after 15.1.0.1
Fix from $1,950 2020-04-30
Big Ip Access Policy Manager MEDIUM 5.4
CVE-2020-5889

On versions 15.1.0-15.1.0.1, 15.0.0-15.0.1.2, and 14.1.0-14.1.2.3, in BIG-IP APM portal access, a specially crafted HTTP request can lead to reflecte…

Fix: after 15.1.0.1
Fix from $1,600 2020-04-30
Big Ip Access Policy Manager HIGH 8.1
CVE-2020-5876

On BIG-IP 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, a race condition exists where mcpd and other proce…

Fix: after 15.1.0.3
Fix from $1,950 2020-04-30
Big Ip Access Policy Manager HIGH 7.5
CVE-2020-5874

On BIG-IP APM 15.0.0-15.0.1.2, 14.1.0-14.1.2.3, and 14.0.0-14.0.1, in certain circumstances, an attacker sending specifically crafted requests to a B…

Fix: after 15.0.1.2
Fix from $1,950 2020-04-30
Big Ip Access Policy Manager HIGH 7.5
CVE-2020-5875

On BIG-IP 15.0.0-15.0.1 and 14.1.0-14.1.2.3, under certain conditions, the Traffic Management Microkernel (TMM) may generate a core file and restart …

Fix: after 15.0.1
Fix from $1,950 2020-04-30
Big Ip Access Policy Manager HIGH 7.5
CVE-2020-5877

On BIG-IP 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, malformed input to the DATAGRAM::tcp iRules comman…

Fix: after 15.1.0.1
Fix from $1,950 2020-04-30
Big Ip Access Policy Manager HIGH 7.5
CVE-2020-5878

On versions 15.1.0-15.1.0.1, 15.0.0-15.0.1.1, and 14.1.0-14.1.2.3, Traffic Management Microkernel (TMM) may restart on BIG-IP Virtual Edition (VE) wh…

Fix: after 15.1.0.1
Fix from $1,950 2020-04-30
Big Ip Application Security Manager HIGH 7.5
CVE-2020-5879

On BIG-IP ASM 11.6.1-11.6.5.1, under certain configurations, the BIG-IP system sends data plane traffic to back-end servers unencrypted, even when a …

Fix: after 11.6.5.1
Fix from $1,950 2020-04-30
Big Ip Access Policy Manager HIGH 7.5
CVE-2020-5881

On versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, and 13.1.0-13.1.3.3, when the BIG-IP Virtual Edition (VE) is configured with VLAN groups and there are …

Fix: after 15.1.0.1
Fix from $1,950 2020-04-30
Big Ip Access Policy Manager HIGH 7.2
CVE-2020-5873

On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.6.1-11.6.5 and BIG-IQ 5.2.0-7.1.0, a user associated with the Resour…

Fix: after 15.0.1
Fix from $1,950 2020-04-30
Big Ip Access Policy Manager HIGH 7.1
CVE-2020-5880

Om BIG-IP 15.0.0-15.0.1.3 and 14.1.0-14.1.2.3, the restjavad process may expose a way for attackers to upload arbitrary files on the BIG-IP system, b…

Fix: after 15.0.1.3
Fix from $1,950 2020-04-30
Big Ip Access Policy Manager HIGH 7.5
CVE-2020-5871

On BIG-IP 14.1.0-14.1.2.3, undisclosed requests can lead to a denial of service (DoS) when sent to BIG-IP HTTP/2 virtual servers. The problem can occ…

Fix: after 14.1.2.3
Fix from $1,950 2020-04-30
Big Ip Access Policy Manager HIGH 7.5
CVE-2020-5872

On BIG-IP 14.1.0-14.1.2.3, 14.0.0-14.0.1, 13.1.0-13.1.3.1, and 12.1.0-12.1.4.1, when processing TLS traffic with hardware cryptographic acceleration …

Fix: after 14.1.2.3
Fix from $1,950 2020-04-30
Big Iq Centralized Management CRITICAL 9.1
CVE-2020-5869

In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization is not secure by TLS and may allow on-path attackers to read / modify confidential data…

Fix: 7.1.0+
Fix from $2,300 2020-04-24
Big Iq Centralized Management HIGH 8.1
CVE-2020-5870

In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization mechanisms do not use any form of authentication for connecting to the peer.

Fix: 7.1.0+
Fix from $1,950 2020-04-24
Big Iq Centralized Management CRITICAL 9.8
CVE-2020-5868

In BIG-IQ 6.0.0-7.0.0, a remote access vulnerability has been discovered that may allow a remote user to execute shell commands on affected systems u…

Fix: after 6.1.0
Fix from $2,300 2020-04-24
Nginx Controller HIGH 8.1
CVE-2020-5867

In versions prior to 3.3.0, the NGINX Controller Agent installer script 'install.sh' uses HTTP instead of HTTPS to check and install packages

Fix: 3.3.0+
Fix from $1,950 2020-04-23
Nginx Controller MEDIUM 5.5
CVE-2020-5866

In versions of NGINX Controller prior to 3.3.0, the helper.sh script, which is used optionally in NGINX Controller to change settings, uses sensitive…

Fix: 3.3.0+
Fix from $1,600 2020-04-23
Nginx Controller HIGH 7.4
CVE-2020-5864

In versions of NGINX Controller prior to 3.2.0, communication between NGINX Controller and NGINX Plus instances skip TLS verification by default.

Fix: 3.3.0+
Fix from $1,950 2020-04-23
Nginx Controller HIGH 8.6
CVE-2020-5863

In NGINX Controller versions prior to 3.2.0, an unauthenticated attacker with network access to the Controller API can create unprivileged user accou…

Fix: 3.2.0+
Fix from $1,950 2020-03-27
Big Iq Centralized Management HIGH 8.1
CVE-2020-5860

On BIG-IP 15.0.0-15.1.0.2, 14.1.0-14.1.2.3, 13.1.0-13.1.3.2, 12.1.0-12.1.5.1, and 11.5.2-11.6.5.1 and BIG-IQ 7.0.0, 6.0.0-6.1.0, and 5.2.0-5.4.0, in …

Fix: after 15.1.0
Fix from $1,950 2020-03-27
Big Iq Centralized Management HIGH 7.8
CVE-2020-5858

On BIG-IP 15.0.0-15.0.1.2, 14.1.0-14.1.2.2, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.5.2-11.6.5.1 and BIG-IQ 7.0.0, 6.0.0-6.1.0, and 5.2.0-5.4.0, users…

Fix: after 15.0.1
Fix from $1,950 2020-03-27
Big Ip Access Policy Manager HIGH 7.5
CVE-2020-5857

On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2.2, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, undisclosed HTTP behavior may lead to a denial of serv…

Fix: after 15.0.1
Fix from $1,950 2020-03-27