Vulnerability index

Browse CVEs

865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Big Ip Access Policy Manager MEDIUM 6.1
CVE-2018-5548

On BIG-IP APM 11.6.0-11.6.3, an insecure AES ECB mode is used for orig_uri parameter in an undisclosed /vdesk link of APM virtual server configured w…

Fix: after 11.6.3
Fix from $1,600 2018-09-13
Big Ip Access Policy Manager Client HIGH 7.8
CVE-2018-5546

The svpn and policyserver components of the F5 BIG-IP APM client prior to version 7.1.7.1 for Linux and macOS runs as a privileged process and can al…

Fix: after 12.1.3
Fix from $1,950 2018-08-17
Big Ip Access Policy Manager Client HIGH 7.8
CVE-2018-5547

Windows Logon Integration feature of F5 BIG-IP APM client prior to version 7.1.7.1 for Windows by default uses Legacy logon mode which uses a SYSTEM …

Mitigation only
Fix from $1,950 2018-08-17
Big Ip Controller HIGH 8.8
CVE-2018-5543

The F5 BIG-IP Controller for Kubernetes 1.0.0-1.5.0 (k8s-bigip-crtl) passes BIG-IP username and password as command line parameters, which may lead t…

Fix: after 1.5.0
Fix from $1,950 2018-07-31
Big Ip Access Policy Manager HIGH 7.5
CVE-2018-5544

When the F5 BIG-IP APM 13.0.0-13.1.1 or 12.1.0-12.1.3 renders certain pages (pages with a logon agent or a confirm box), the BIG-IP APM may disclose …

Fix: after 13.1.1
Fix from $1,950 2018-07-31
Big Ip Local Traffic Manager HIGH 8.1
CVE-2018-5542

F5 BIG-IP 13.0.0-13.0.1, 12.1.0-12.1.3.6, or 11.2.1-11.6.3.2 HTTPS health monitors do not validate the identity of the monitored server.

Fix: after 13.0.1
Fix from $1,950 2018-07-25
Big Ip Local Traffic Manager HIGH 7.5
CVE-2018-5530

F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.5, or 11.6.0-11.6.3.1 virtual servers with HTTP/2 profiles enabled are vulnerable to "HPACK Bomb".

Fix: after 13.1.0.5
Fix from $1,950 2018-07-25
Big Ip Access Policy Manager HIGH 7.5
CVE-2018-5536

A remote attacker via undisclosed measures, may be able to exploit an F5 BIG-IP APM 13.0.0-13.1.0.7 or 12.1.0-12.1.3.5 virtual server configured with…

Fix: after 13.1.0.7
Fix from $1,950 2018-07-25
Big Ip Application Security Manager HIGH 7.5
CVE-2018-5539

Under certain conditions, on F5 BIG-IP ASM 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, 11.6.0-11.6.3.1, 11.5.1-11.5.6, or 11.2.1, when processing CSRF protecti…

Fix: after 13.1.0
Fix from $1,950 2018-07-25
Big Ip Application Security Manager HIGH 7.5
CVE-2018-5541

When F5 BIG-IP ASM 13.0.0-13.1.0.1, 12.1.0-12.1.3.5, 11.6.0-11.6.3.1, or 11.5.1-11.5.6 is processing HTTP requests, an unusually large number of para…

Fix: after 13.1.0
Fix from $1,950 2018-07-25
Big Ip Local Traffic Manager HIGH 7.4
CVE-2018-5531

Through undisclosed methods, on F5 BIG-IP 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, 11.6.0-11.6.3.1, or 11.2.1-11.5.6, adjacent network attackers can cause a…

Fix: after 13.1.0.7
Fix from $1,950 2018-07-25
Big Ip Local Traffic Manager MEDIUM 5.3
CVE-2018-5537

A remote attacker may be able to disrupt services on F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.5, 11.6.0-11.6.3.1, or 11.2.1-11.5.6 if the TMM virtual…

Fix: after 13.1.0.5
Fix from $1,600 2018-07-25
Big Ip Local Traffic Manager HIGH 7.5
CVE-2018-5533

Under certain conditions on F5 BIG-IP 13.0.0, 12.1.0-12.1.2, 11.6.0-11.6.3.1, or 11.5.0-11.5.6, TMM may core while processing SSL forward proxy traff…

Fix: after 12.1.2
Fix from $1,950 2018-07-19
Big Ip Local Traffic Manager HIGH 7.5
CVE-2018-5534

Under certain conditions on F5 BIG-IP 13.1.0-13.1.0.5, 13.0.0, 12.1.0-12.1.3.1, 11.6.0-11.6.3.1, or 11.5.0-11.5.6, TMM may core while processing SSL …

Fix: after 13.1.0.5
Fix from $1,950 2018-07-19
Big Ip Local Traffic Manager HIGH 7.5
CVE-2018-5535

On F5 BIG-IP 14.0.0, 13.0.0-13.1.0, 12.1.0-12.1.3, or 11.5.1-11.6.3 specifically crafted HTTP responses, when processed by a Virtual Server with an a…

Fix: after 13.1.1
Fix from $1,950 2018-07-19
Big Ip Local Traffic Manager MEDIUM 5.3
CVE-2018-5532

On F5 BIG-IP 13.0.0, 12.1.0-12.1.2, 11.6.0-11.6.3.1, or 11.2.1-11.5.6 a domain name cached within the DNS Cache of TMM may continue to be resolved by…

Fix: after 12.1.2
Fix from $1,600 2018-07-19
Big Ip Access Policy Manager HIGH 7.8
CVE-2018-5529

The svpn component of the F5 BIG-IP APM client prior to version 7.1.7 for Linux and Mac OS X runs as a privileged process and can allow an unprivileg…

Fix: after 7150
Fix from $1,950 2018-07-12
Big Ip Access Policy Manager MEDIUM 5.3
CVE-2018-5528

Under certain conditions, TMM may restart and produce a core file while processing APM data on BIG-IP 13.0.1 or 13.1.0.4-13.1.0.7.

Fix: after 13.1.0.7
Fix from $1,600 2018-06-27
Big Ip Access Policy Manager HIGH 7.5
CVE-2018-5527

On BIG-IP 13.1.0-13.1.0.7, a remote attacker using undisclosed methods against virtual servers configured with a Client SSL or Server SSL profile tha…

Fix: after 13.1.0.7
Fix from $1,950 2018-06-27
Big Ip Application Acceleration Manager HIGH 7.5
CVE-2018-5513

On F5 BIG-IP 13.1.0-13.1.0.3, 13.0.0, 12.1.0-12.1.3.3, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, a malformed TLS handshake causes TMM to crash leadi…

Fix: after 13.1.0.4
Fix from $1,950 2018-06-01
Big Ip Application Acceleration Manager HIGH 7.2
CVE-2018-5523

On F5 BIG-IP 13.1.0-13.1.0.3, 13.0.0, 12.1.0-12.1.3.1, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1 and Enterprise Manager 3.1.1, when authenticated adm…

Fix: after 12.1.3
Fix from $1,950 2018-06-01
Big Ip Application Security Manager MEDIUM 6.5
CVE-2018-5526

Under certain conditions, on F5 BIG-IP ASM 13.1.0-13.1.0.5, Behavioral DOS (BADOS) protection may fail during an attack.

Fix: after 13.1.0.5
Fix from $1,600 2018-06-01
Big Ip Application Acceleration Manager MEDIUM 6.1
CVE-2018-5521

On F5 BIG-IP 12.1.0-12.1.3.1, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, carefully crafted URLs can be used to reflect arbitrary content into GeoIP l…

Fix: after 12.1.3
Fix from $1,600 2018-06-01
Big Ip Application Acceleration Manager MEDIUM 5.9
CVE-2018-5522

On F5 BIG-IP 13.0.0, 12.0.0-12.1.2, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, when processing DIAMETER transactions with carefully crafted attribute…

Fix: after 12.1.2
Fix from $1,600 2018-06-01
Big Ip Application Acceleration Manager MEDIUM 5.3
CVE-2017-6153

Features in F5 BIG-IP 13.0.0-13.1.0.3, 12.1.0-12.1.3.1, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1 system that utilizes inflate functionality directly…

Fix: after 12.1.3
Fix from $1,600 2018-06-01
Big Ip Application Acceleration Manager MEDIUM 5.3
CVE-2018-5524

Under certain conditions, on F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.1, or 11.6.1 HF2-11.6.3.1, virtual servers configured with Client SSL or Server…

Fix: after 13.0.1
Fix from $1,600 2018-06-01
Big Ip Local Traffic Manager HIGH 7.5
CVE-2018-5512

On F5 BIG-IP 13.1.0-13.1.0.5, when Large Receive Offload (LRO) and SYN cookies are enabled (default settings), undisclosed traffic patterns may cause…

Fix: after 13.1.0.5
Fix from $1,950 2018-05-02
Big Ip Local Traffic Manager HIGH 7.5
CVE-2018-5514

On F5 BIG-IP 13.1.0-13.1.0.5, maliciously crafted HTTP/2 request frames can lead to denial of service. There is data plane exposure for virtual serve…

Fix: after 13.1.0.5
Fix from $1,950 2018-05-02
Big Ip Local Traffic Manager HIGH 7.5
CVE-2018-5517

On F5 BIG-IP 13.1.0-13.1.0.5, malformed TCP packets sent to a self IP address or a FastL4 virtual server may cause an interruption of service. The co…

Fix: after 13.1.0.5
Fix from $1,950 2018-05-02
Big Ip Local Traffic Manager MEDIUM 5.4
CVE-2018-5518

On F5 BIG-IP 13.0.0-13.1.0.5 or 12.0.0-12.1.3.3, malicious root users with access to a VCMP guest can cause a disruption of service on adjacent VCMP …

Fix: after 13.1.0
Fix from $1,600 2018-05-02