Vulnerability index

Browse CVEs

865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Big Ip Local Traffic Manager MEDIUM 5.9
CVE-2017-6137

In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, PSM, WebAccelerator, and WebSafe 11.6.1 HF1, 12.0.0 HF…

Mitigation only
Fix from $1,600 2017-05-09
Big Ip Access Policy Manager MEDIUM 5.3
CVE-2017-0302

In F5 BIG-IP APM 12.0.0 through 12.1.2 and 13.0.0, an authenticated user with an established access session to the BIG-IP APM system may be able to c…

Mitigation only
Fix from $1,600 2017-05-09
Big Ip Local Traffic Manager HIGH 7.5
CVE-2017-6128

An attacker may be able to cause a denial-of-service (DoS) attack against the sshd component in F5 BIG-IP, Enterprise Manager, BIG-IQ, and iWorkflow.

No fix yet
Fix from $1,950 2017-05-01
Big Ip Access Policy Manager MEDIUM 5.3
CVE-2016-7467

The TMM SSO plugin in F5 BIG-IP APM 12.0.0 - 12.1.1, 11.6.0 - 11.6.1 HF1, 11.5.4 - 11.5.4 HF2, when configured as a SAML Identity Provider with a Ser…

Mitigation only
Fix from $1,600 2017-04-11
Ssl Intercept Iapp CRITICAL 9.8
CVE-2017-0305

F5 SSL Intercept iApp version 1.5.0 - 1.5.7 is vulnerable to an unauthenticated, remote attack that may allow modification of the BIG-IP system confi…

Mitigation only
Fix from $2,300 2017-04-06
Ssl Intercept Iapp HIGH 7.4
CVE-2017-6130

F5 SSL Intercept iApp 1.5.0 - 1.5.7 and SSL Orchestrator 2.0 is vulnerable to a Server-Side Request Forgery (SSRF) attack when deployed using the Dyn…

Mitigation only
Fix from $1,950 2017-04-06
Big Ip Local Traffic Manager HIGH 7.5
CVE-2016-9252

The Traffic Management Microkernel (TMM) in F5 BIG-IP before 11.5.4 HF3, 11.6.x before 11.6.1 HF2 and 12.x before 12.1.2 does not properly handle min…

Mitigation only
Fix from $1,950 2017-03-27
Big Ip Local Traffic Manager MEDIUM 5.5
CVE-2016-7474

In some cases the MCPD binary cache in F5 BIG-IP devices may allow a user with Advanced Shell access, or privileges to generate a qkview, to temporar…

Mitigation only
Fix from $1,600 2017-03-27
Big Ip Local Traffic Manager MEDIUM 5.9
CVE-2016-7468

An unauthenticated remote attacker may be able to disrupt services on F5 BIG-IP 11.4.1 - 11.5.4 devices with maliciously crafted network traffic. Thi…

Mitigation only
Fix from $1,600 2017-03-23
Big Ip Local Traffic Manager MEDIUM 5.9
CVE-2016-9245

In F5 BIG-IP systems 12.1.0 - 12.1.2, malicious requests made to virtual servers with an HTTP profile can cause the TMM to restart. The issue is expo…

Mitigation only
Fix from $1,600 2017-03-07
Big Ip Access Policy Manager MEDIUM 5.3
CVE-2016-6249

F5 BIG-IP 12.0.0 and 11.5.0 - 11.6.1 REST requests which timeout during user account authentication may log sensitive attributes such as passwords in…

Mitigation only
Fix from $1,600 2017-02-20
Big Ip Local Traffic Manager HIGH 7.5
CVE-2016-9244EPSS 74%

A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may leak up to 31 bytes of unini…

No fix yet
Fix from $1,950 2017-02-09
Big Ip Local Traffic Manager HIGH 7.5
CVE-2016-9249

An undisclosed traffic pattern received by a BIG-IP Virtual Server with TCP Fast Open enabled may cause the Traffic Management Microkernel (TMM) to r…

Mitigation only
Fix from $1,950 2017-01-31
Big Ip Local Traffic Manager MEDIUM 5.9
CVE-2016-9247

Under certain conditions for BIG-IP systems using a virtual server with an associated FastL4 profile and TCP analytics profile, a specific sequence o…

Mitigation only
Fix from $1,600 2017-01-10
Big Ip Local Traffic Manager MEDIUM 5.9
CVE-2016-5024

Virtual servers in F5 BIG-IP systems 11.6.1 before 11.6.1 HF1 and 12.1.x before 12.1.2, when configured to parse RADIUS messages via an iRule, allow …

Mitigation only
Fix from $1,600 2017-01-03
Nginx HIGH 7.8
CVE-2016-1247

The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS, before 1.10.0-0ubuntu0.16.0…

Fix: after 1.10.1
Fix from $1,950 2016-11-29
Big Ip Local Traffic Manager CRITICAL 9.8
CVE-2016-5745

F5 BIG-IP LTM systems 11.x before 11.2.1 HF16, 11.3.x, 11.4.x before 11.4.1 HF11, 11.5.0, 11.5.1 before HF11, 11.5.2, 11.5.3, 11.5.4 before HF2, 11.6…

Mitigation only
Fix from $2,300 2016-10-05
Big Ip Policy Enforcement Manager CRITICAL 9.8
CVE-2016-5700EPSS 6%

Virtual servers in F5 BIG-IP systems 11.5.0, 11.5.1 before HF11, 11.5.2, 11.5.3, 11.5.4 before HF2, 11.6.0 before HF8, 11.6.1 before HF1, 12.0.0 befo…

Mitigation only
Fix from $2,300 2016-10-03
Big Ip Local Traffic Manager HIGH 7.5
CVE-2016-6876

The RESOLV::lookup iRule command in F5 BIG-IP LTM, APM, ASM, and Link Controller 10.2.1 through 10.2.4, 11.2.1, 11.4.x, 11.5.x before 11.5.4 HF2, 11.…

Mitigation only
Fix from $1,950 2016-09-07
Big Ip Link Controller CRITICAL 9.8
CVE-2016-5022

F5 BIG-IP LTM, Analytics, APM, ASM, and Link Controller 11.2.x before 11.2.1 HF16, 11.3.x, 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.6.1 HF1…

Mitigation only
Fix from $2,300 2016-09-07
Big Ip Edge Gateway HIGH 7.5
CVE-2016-5023

Virtual servers in F5 BIG-IP systems 11.2.1 HF11 through HF15, 11.4.1 HF4 through HF10, 11.5.3 through 11.5.4, 11.6.0 HF5 through HF7, and 12.0.0, wh…

Mitigation only
Fix from $1,950 2016-08-26
Big Ip Application Acceleration Manager HIGH 7.5
CVE-2016-5736

The default configuration of the IPsec IKE peer listener in F5 BIG-IP LTM, Analytics, APM, ASM, and Link Controller 11.2.1 before HF16, 11.4.x, 11.5.…

Mitigation only
Fix from $1,950 2016-08-19
Big Ip Global Traffic Manager HIGH 7.5
CVE-2015-8022

The Configuration utility in F5 BIG-IP LTM, Analytics, APM, ASM, GTM, and Link Controller 11.x before 11.2.1 HF16, 11.3.x, 11.4.x before 11.4.1 HF10,…

Mitigation only
Fix from $1,950 2016-08-19
Traffix Signaling Delivery Controller HIGH 7.5
CVE-2015-5738

The RSA-CRT implementation in the Cavium Software Development Kit (SDK) 2.x, when used on OCTEON II CN6xxx Hardware on Linux to support TLS with Perf…

Fix: after 4.4.0
Fix from $1,950 2016-07-26
Big Ip Wan Optimization Manager HIGH 8.8
CVE-2016-5020

F5 BIG-IP before 12.0.0 HF3 allows remote authenticated users to modify the account configuration of users with the Resource Administration role and …

Mitigation only
Fix from $1,950 2016-06-30
Big Ip Access Policy Manager MEDIUM 5.3
CVE-2016-3687

Open redirect vulnerability in F5 BIG-IP APM 11.2.1, 11.4.x, 11.5.x, and 11.6.x before 11.6.0 HF6 and Edge Gateway 11.2.1, when using multi-domain si…

Mitigation only
Fix from $1,600 2016-06-16
Big Ip Application Acceleration Manager HIGH 7.5
CVE-2016-4545

Virtual servers in F5 BIG-IP 11.5.4, when SSL profiles are enabled, allow remote attackers to cause a denial of service (resource consumption and Tra…

Mitigation only
Fix from $1,950 2016-06-07
Big Ip Access Policy Manager MEDIUM 5.9
CVE-2015-8099

F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.x, 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, 11.6.x before 11.6.1, and …

Mitigation only
Fix from $1,600 2016-05-13
Big Ip Edge Gateway MEDIUM 5.9
CVE-2016-3686

The Single Sign-On (SSO) feature in F5 BIG-IP APM 11.x before 11.6.0 HF6 and BIG-IP Edge Gateway 11.0.0 through 11.3.0 might allow remote attackers t…

Mitigation only
Fix from $1,600 2016-04-13
Big Iq Security HIGH 7.4
CVE-2016-2084

F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.x, 11.4.x before 11.4.1 build 685-HF10, 11.5.1 before build 10.104.180, 11.5.2…

Mitigation only
Fix from $1,950 2016-04-13