Vulnerability index

Browse CVEs

865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ssl Orchestrator HIGH 7.5
CVE-2019-6674

On F5 SSL Orchestrator 15.0.0-15.0.1 and 14.0.0-14.1.2, TMM may crash when processing SSLO data in a service-chaining configuration.

Fix: after 15.0.1
Fix from $1,950 2019-11-27
Big Ip Link Controller CRITICAL 9.8
CVE-2019-6675

BIG-IP configurations using Active Directory, LDAP, or Client Certificate LDAP for management authentication with multiple servers are exposed to a v…

Fix: after 15.0.1.0.48.11-eng_hotfix
Fix from $2,300 2019-11-26
Big Ip Access Policy Manager HIGH 7.5
CVE-2019-6659

On version 14.0.0-14.1.0.1, BIG-IP virtual servers with TLSv1.3 enabled may experience a denial of service due to undisclosed incoming messages.

Fix: 14.1.0.2+
Fix from $1,950 2019-11-15
Big Ip Access Policy Manager HIGH 7.5
CVE-2019-6660

On BIG-IP 14.1.0-14.1.2, 14.0.0-14.0.1, and 13.1.0-13.1.1, undisclosed HTTP requests may consume excessive amounts of systems resources which may lea…

Fix: 13.1.3 / 14.0.1.1+
Fix from $1,950 2019-11-15
Big Ip Access Policy Manager HIGH 7.5
CVE-2019-6661

When the BIG-IP APM 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.4.1, or 11.5.1-11.6.5 system processes certain requests, the APD/APMD …

Fix: 11.6.5.1 / 12.1.5+
Fix from $1,950 2019-11-15
Big Ip Access Policy Manager HIGH 7.5
CVE-2019-6664

On BIG-IP 15.0.0 and 14.1.0-14.1.0.6, under certain conditions, network protections on the management port do not follow current best practices.

Fix: 14.1.2+
Fix from $1,950 2019-11-15
Big Ip Access Policy Manager MEDIUM 6.5
CVE-2019-6662

On BIG-IP 13.1.0-13.1.1.4, sensitive information is logged into the local log files and/or remote logging targets when restjavad processes an invalid…

Fix: 13.1.1.5+
Fix from $1,600 2019-11-15
Big Ip Access Policy Manager MEDIUM 5.5
CVE-2019-6663

The BIG-IP 15.0.0-15.0.1, 14.0.0-14.1.2.2, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.1-11.6.5.1, BIG-IQ 7.0.0, 6.0.0-6.1.0, and 5.2.0-5.4.0, iWorkflow…

Fix: after 15.0.1
Fix from $1,600 2019-11-15
Big Ip Advanced Firewall Manager MEDIUM 6.1
CVE-2019-6657

On BIG-IP 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, a reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of …

Fix: after 13.1.3
Fix from $1,600 2019-11-01
Big Ip Local Traffic Manager MEDIUM 5.9
CVE-2019-6471

A race condition which may occur when discarding malformed packets can result in BIND exiting due to a REQUIRE assertion failure in dispatch.c. Versi…

Fix: after 13.1.1
Fix from $1,600 2019-10-09
Big Ip Local Traffic Manager HIGH 7.5
CVE-2018-5743EPSS 6%

By design, BIND is intended to limit the number of TCP clients that can be connected at any given time. The number of allowed connections is a tunabl…

Fix: after 14.1.1
Fix from $1,950 2019-10-09
Traffix Signaling Delivery Controller HIGH 7.5
CVE-2018-14882

The ICMPv6 parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp6.c.

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03
Traffix Signaling Delivery Controller HIGH 7.5
CVE-2018-16229EPSS 7%

The DCCP parser in tcpdump before 4.9.3 has a buffer over-read in print-dccp.c:dccp_print_option().

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03
Traffix Signaling Delivery Controller HIGH 7.0
CVE-2018-14879

The command-line argument parser in tcpdump before 4.9.3 has a buffer overflow in tcpdump.c:get_next_file().

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03
Traffix Signaling Delivery Controller HIGH 7.5
CVE-2018-14462

The ICMP parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp.c:icmp_print().

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03
Traffix Signaling Delivery Controller HIGH 7.5
CVE-2018-14463

The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 2, a different vulnerability than CVE-20…

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03
Traffix Signaling Delivery Controller HIGH 7.5
CVE-2018-14465

The RSVP parser in tcpdump before 4.9.3 has a buffer over-read in print-rsvp.c:rsvp_obj_print().

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03
Traffix Signaling Delivery Controller HIGH 7.5
CVE-2018-14469EPSS 5%

The IKEv1 parser in tcpdump before 4.9.3 has a buffer over-read in print-isakmp.c:ikev1_n_print().

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03
Big Ip Access Policy Manager HIGH 7.5
CVE-2019-6656

BIG-IP APM Edge Client before version 7.1.8 (7180.2019.508.705) logs the full apm session ID in the log files. Vulnerable versions of the client are …

Fix: 13.1.3 / 14.0.0.5+
Fix from $1,950 2019-09-25
Big Ip Application Acceleration Manager MEDIUM 5.3
CVE-2019-6655

On versions 13.0.0-13.1.0.1, 12.1.0-12.1.4.1, 11.6.1-11.6.4, and 11.5.1-11.5.9, BIG-IP platforms where AVR, ASM, APM, PEM, AFM, and/or AAM is provisi…

Fix: after 13.1.0.1
Fix from $1,600 2019-09-25
Big Iq Centralized Management MEDIUM 6.5
CVE-2019-6652

In BIG-IQ 6.0.0-6.1.0, services for stats do not require authentication nor do they implement any form of Transport Layer Security (TLS).

Fix: after 6.1.0
Fix from $1,600 2019-09-25
Big Iq Centralized Management MEDIUM 5.4
CVE-2019-6653

There is a Stored Cross Site Scripting vulnerability in the undisclosed page of a BIG-IQ 6.0.0-6.1.0 or 5.2.0-5.4.0 system. The attack can be stored …

Fix: after 6.1.0
Fix from $1,600 2019-09-25
Big Ip Local Traffic Manager MEDIUM 5.3
CVE-2019-6651

In BIG-IP 15.0.0, 14.1.0-14.1.0.6, 14.0.0-14.0.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, 11.5.1-11.6.4, BIG-IQ 7.0.0, 6.0.0-6.1.0,5.2.0-5.4.0, iWorkflow…

Fix: after 14.1.0.6
Fix from $1,600 2019-09-25
Big Ip Application Security Manager CRITICAL 9.1
CVE-2019-6649

F5 BIG-IP 15.0.0, 14.1.0-14.1.0.6, 14.0.0-14.0.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, 11.6.0-11.6.4, and 11.5.1-11.5.9 and Enterprise Manager 3.1.1 m…

Fix: after 13.1.1
Fix from $2,300 2019-09-20
Big Ip Application Security Manager CRITICAL 9.1
CVE-2019-6650

F5 BIG-IP ASM 15.0.0, 14.1.0-14.1.0.6, 14.0.0-14.0.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, 11.6.0-11.6.4, and 11.5.1-11.5.9 may expose sensitive infor…

Fix: after 13.1.1
Fix from $2,300 2019-09-20
Big Ip Access Policy Manager HIGH 8.8
CVE-2019-6646

On BIG-IP 11.5.2-11.6.4 and Enterprise Manager 3.1.1, REST users with guest privileges may be able to escalate their privileges and run commands with…

Fix: after 11.6.4
Fix from $1,950 2019-09-04
Big Ip Local Traffic Manager HIGH 7.5
CVE-2019-6643

On versions 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.2, 12.1.0-12.1.4.1, and 11.5.2-11.6.4, an attacker sending specifically crafted DHCPv6 requ…

Fix: after 13.1.1
Fix from $1,950 2019-09-04
Big Ip Local Traffic Manager CRITICAL 9.4
CVE-2019-6644

Similar to the issue identified in CVE-2018-12120, on versions 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.2, and 12.1.0-12.1.4 BIG-IP will bind a …

Fix: after 13.1.2
Fix from $2,300 2019-09-04
Big Ip Local Traffic Manager MEDIUM 5.3
CVE-2019-6647

On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.2, 12.1.0-12.1.4.1, 11.5.2-11.6.4, when processing authentication attempts for control-plane …

Fix: after 13.1.1
Fix from $1,600 2019-09-04
Big Ip Local Traffic Manager HIGH 7.5
CVE-2019-6645

On BIG-IP 14.0.0-14.1.0.5, 13.0.0-13.1.2, 12.1.0-12.1.4.1, 11.5.2-11.6.4, FTP traffic passing through a Virtual Server with both an active FTP profil…

Fix: after 13.1.1
Fix from $1,950 2019-09-04