Vulnerability index

Browse CVEs

865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Big Ip Access Policy Manager MEDIUM 5.3
CVE-2025-58424

On BIG-IP systems, undisclosed traffic can cause data corruption and unauthorized data modification in protocols which do not have message integrity …

Fix: 15.1.10.8 / 16.1.6+
Fix from $1,600 2025-10-15
Big Ip Ssl Orchestrator HIGH 7.5
CVE-2025-55036

When BIG-IP SSL Orchestrator explicit forward proxy is configured on a virtual server and the proxy connect feature is enabled, undisclosed traffic m…

Fix: 15.1.10.8 / 16.1.6+
Fix from $1,950 2025-10-15
Big Ip Application Security Manager HIGH 7.5
CVE-2025-55669

When the BIG-IP Advanced WAF and ASM security policy and a server-side HTTP/2 profile are configured on a virtual server, undisclosed traffic can cau…

Fix: 16.1.6+
Fix from $1,950 2025-10-15
Big Ip Next Cloud Native Network Functions MEDIUM 6.5
CVE-2025-55670

On BIG-IP Next CNF, BIG-IP Next SPK, and BIG-IP Next for Kubernetes systems, repeated undisclosed API calls can cause the Traffic Management Microker…

Fix: after 1.9.2
Fix from $1,600 2025-10-15
Big Ip Access Policy Manager HIGH 7.5
CVE-2025-54854

When a BIG-IP APM OAuth access profile (Resource Server or Resource Client) is configured on a virtual server, undisclosed traffic can cause the apmd…

Fix: 15.1.10.8 / 16.1.6.1+
Fix from $1,950 2025-10-15
Big Ip Advanced Web Application Firewall HIGH 7.5
CVE-2025-54858

When a BIG-IP Advanced WAF or BIG-IP ASM Security Policy is configured with a JSON content profile that has a malformed JSON schema, and the security…

Fix: 15.1.10.8 / 16.1.6.1+
Fix from $1,950 2025-10-15
Big Ip Next Cloud Native Network Functions HIGH 7.5
CVE-2025-54479

When a classification profile is configured on a virtual server without an HTTP or HTTP/2 profile, undisclosed requests can cause the Traffic Managem…

Fix: 15.1.10.8 / 16.1.6.1+
Fix from $1,950 2025-10-15
Big Ip Next Cloud Native Network Functions MEDIUM 6.5
CVE-2025-54805

When an iRule is configured on a virtual server via the declarative API, upon re-instantiation, the cleanup process can cause an increase in the Traf…

Fix: after 1.9.2
Fix from $1,600 2025-10-15
Big Ip Access Policy Manager CRITICAL 9.8
CVE-2025-53521 KEV

When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).   Note: Softw…

Fix: 15.1.10.8 / 16.1.6.1+
Fix from $2,300 2025-10-15
Big Ip Access Policy Manager HIGH 8.7
CVE-2025-53868

When running in Appliance mode, a highly privileged authenticated attacker with access to SCP and SFTP may be able to bypass Appliance mode restricti…

Fix: 15.1.10.8 / 16.1.6.1+
Fix from $1,950 2025-10-15
Big Ip Next Cloud Native Network Functions HIGH 7.5
CVE-2025-48008

When a TCP profile with Multipath TCP (MPTCP) enabled is configured on a virtual server, undisclosed traffic along with conditions beyond the attacke…

Fix: 15.1.10.8 / 16.1.6+
Fix from $1,950 2025-10-15
Big Ip Access Policy Manager HIGH 7.5
CVE-2025-53474

When an iRule using an ILX::call command is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to…

Fix: 15.1.1.0.8 / 16.1.6.1+
Fix from $1,950 2025-10-15
Big Ip Access Policy Manager HIGH 7.5
CVE-2025-53856

When a virtual server, network address translation (NAT) object, or secure network address translation (SNAT) object uses the embedded Packet Velocit…

Fix: 15.1.10.8 / 16.1.6.1+
Fix from $1,950 2025-10-15
Big Ip Ssl Orchestrator HIGH 7.5
CVE-2025-41430

When BIG-IP SSL Orchestrator is enabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versi…

Fix: 16.1.4 / 17.1.3+
Fix from $1,950 2025-10-15
Big Ip Next Cloud Native Network Functions HIGH 7.5
CVE-2025-46706

When an iRule containing the HTTP::respond command is configured on a virtual server, undisclosed requests can cause an increase in memory resource u…

Fix: 16.1.6 / 17.1.2.2+
Fix from $1,950 2025-10-15
Big Ip Access Policy Manager MEDIUM 6.5
CVE-2025-47148

When the BIG-IP system is configured as both a Security Assertion Markup Language (SAML) service provider (SP) and Identity Provider (IdP), with sing…

Fix: 15.1.10.8 / 16.1.6.1+
Fix from $1,600 2025-10-15
F5os A MEDIUM 6.5
CVE-2025-47150

When SNMP is configured on F5OS Appliance and Chassis systems, undisclosed requests can cause an increase in SNMP memory resource utilization.  Note:…

Fix: 1.5.3 / 1.6.4+
Fix from $1,600 2025-10-15
F5 Access HIGH 7.4
CVE-2025-54809

F5 Access for Android before version 3.1.2 which uses HTTPS does not verify the remote endpoint identity. Note: Software versions which have rea…

Fix: 3.1.2+
Fix from $1,950 2025-08-13
Big Ip Access Policy Manager MEDIUM 5.3
CVE-2025-54500

An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to break the max concurrent streams…

Fix: 15.1.10.8 / 16.1.6.1+
Fix from $1,600 2025-08-13
Big Ip Access Policy Manager HIGH 7.5
CVE-2025-52585

When a BIG-IP LTM Client SSL profile is configured on a virtual server with SSL Forward Proxy enabled and Anonymous Diffie-Hellman (ADH) ciphers enab…

Fix: 15.1.10.8 / 16.1.6+
Fix from $1,950 2025-08-13
Big Ip Access Policy Manager HIGH 7.5
CVE-2025-46405

When Network Access is configured on a BIG-IP APM virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate…

Fix: 15.1.10.8 / 16.1.6+
Fix from $1,950 2025-08-13
Big Ip Access Policy Manager HIGH 7.3
CVE-2025-48500

A missing file integrity check vulnerability exists on MacOS F5 VPN browser client installer that may allow a local, authenticated attacker with acce…

Fix: 15.1.10.8 / 16.1.6.1+
Fix from $1,950 2025-08-13
F5os A HIGH 8.8
CVE-2025-46265

On F5OS, an improper authorization vulnerability exists where remotely authenticated users (LDAP, RADIUS, TACACS+) may be authorized with higher priv…

Fix: after 1.6.2
Fix from $1,950 2025-05-07
Big Ip Access Policy Manager HIGH 7.5
CVE-2025-36557

When an HTTP profile with the Enforce RFC Compliance option is configured on a virtual server, undisclosed requests can cause the Traffic Management …

Fix: 16.1.5 / 17.1.2+
Fix from $1,950 2025-05-07
Big Ip Access Policy Manager HIGH 7.5
CVE-2025-41399

When a Stream Control Transmission Protocol (SCTP) profile is configured on a virtual server, undisclosed requests can cause an increase in memory re…

Fix: 15.1.9 / 16.1.4+
Fix from $1,950 2025-05-07
Big Ip Access Policy Manager HIGH 7.5
CVE-2025-41414

When HTTP/2 client and server profile is configured on a virtual server, undisclosed requests can cause TMM to terminate.  Note: Software versio…

Fix: 16.1.5 / 17.1.2+
Fix from $1,950 2025-05-07
Big Ip Access Policy Manager HIGH 7.5
CVE-2025-41431

When connection mirroring is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate in …

Mitigation only
Fix from $1,950 2025-05-07
Big Ip Access Policy Manager HIGH 7.5
CVE-2025-41433

When a Session Initiation Protocol (SIP) message routing framework (MRF) application layer gateway (ALG) profile is configured on a Message Routing v…

Fix: 16.1.5 / 17.1.2+
Fix from $1,950 2025-05-07
F5os A MEDIUM 6.0
CVE-2025-43878

When running in Appliance mode, an authenticated attacker assigned the Administrator or Resource Administrator role may be able to bypass Appliance m…

Fix: 1.8.0+
Fix from $1,600 2025-05-07
F5os A HIGH 8.1
CVE-2025-36546

On an F5OS system, if the root user had previously configured the system to allow login via SSH key-based authentication, and then enabled Appliance …

Fix: 1.5.3+
Fix from $1,950 2025-05-07