Vulnerability index

Browse CVEs

865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Big Ip Policy Enforcement Manager HIGH 7.5
CVE-2025-35995

When a BIG-IP PEM system is licensed with URL categorization, and the URL categorization policy or an iRule with the urlcat command is enabled on a v…

Fix: 15.1.10.7.0.4.5 / 16.1.6+
Fix from $1,950 2025-05-07
Big Ip Access Policy Manager HIGH 7.5
CVE-2025-36504

When a BIG-IP HTTP/2 httprouter profile is configured on a virtual server, undisclosed responses can cause an increase in memory resource utilization…

Fix: 16.1.6 / 17.1.2+
Fix from $1,950 2025-05-07
Big Ip Access Policy Manager HIGH 7.5
CVE-2025-36525

When a BIG-IP APM virtual server is configured to use a PingAccess profile, undisclosed requests can cause TMM to terminate. Note: Software versio…

Fix: 15.1.10.7.0.4.5 / 16.1.6+
Fix from $1,950 2025-05-07
Big Ip Access Policy Manager HIGH 8.7
CVE-2025-31644EPSS 24%

When running in Appliance mode, a command injection vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command which m…

Fix: 15.1.10.7 / 16.1.6+
Fix from $1,950 2025-05-07
Nginx Unit MEDIUM 5.3
CVE-2025-1695

In NGINX Unit before version 1.34.2 with the Java Language Module in use, undisclosed requests can lead to an infinite loop and cause an increase in …

Fix: 1.34.2+
Fix from $1,600 2025-03-04
Big Ip Application Security Manager HIGH 7.5
CVE-2025-24326

When BIG-IP Advanced WAF/ASM Behavioral DoS (BADoS) TLS Signatures feature is configured, undisclosed traffic can case an increase in memory resource…

Fix: 15.1.10.6.0.11.6-ENG / 16.1.5+
Fix from $1,950 2025-02-05
Big Ip Policy Enforcement Manager HIGH 7.5
CVE-2025-24497

When URL categorization is configured on a virtual server, undisclosed requests can cause TMM to terminate.  Note: Software versions which have reach…

Fix: 17.1.2+
Fix from $1,950 2025-02-05
Big Ip Access Policy Manager HIGH 8.0
CVE-2025-24320

A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run Ja…

Fix: 15.1.10.6 / 16.1.5.2+
Fix from $1,950 2025-02-05
Big Ip Advanced Firewall Manager HIGH 7.5
CVE-2025-24312

When BIG-IP AFM is provisioned with IPS module enabled and protocol inspection profile is configured on a virtual server or firewall rule or policy, …

Fix: 1.4.0 / 15.1.10.6.0.11.6+
Fix from $1,950 2025-02-05
Big Ip Next Central Manager MEDIUM 6.5
CVE-2025-24319

When BIG-IP Next Central Manager is running, undisclosed requests to the BIG-IP Next Central Manager API can cause the BIG-IP Next Central Manager No…

Fix: 20.3.0+
Fix from $1,600 2025-02-05
Big Ip Access Policy Manager HIGH 8.7
CVE-2025-23239

When running in Appliance mode, and logged into a highly-privileged role, an authenticated remote command injection vulnerability exists in an undisc…

Mitigation only
Fix from $1,950 2025-02-05
Big Ip Next Service Proxy For Kubernetes HIGH 7.5
CVE-2025-22846

When SIP Session and Router ALG profiles are configured on a Message Routing type virtual server, undisclosed traffic can cause the Traffic Managemen…

Fix: 1.7.7 / 15.1.10.6.0.11.6-ENG+
Fix from $1,950 2025-02-05
Big Ip Policy Enforcement Manager HIGH 7.5
CVE-2025-22891

When BIG-IP PEM Control Plane listener Virtual Server is configured with Diameter Endpoint profile, undisclosed traffic can cause the Virtual Server …

Fix: 15.1.10.6.0.11.6 / 16.1.5+
Fix from $1,950 2025-02-05
Big Ip Access Policy Manager HIGH 7.5
CVE-2025-23412

When BIG-IP APM Access Profile is configured on a virtual server, undisclosed request can cause TMM to terminate. Note: Software versions whic…

Fix: 16.1.5 / 17.1.2+
Fix from $1,950 2025-02-05
Big Ip Access Policy Manager HIGH 7.5
CVE-2025-21087

When Client or Server SSL profiles are configured on a Virtual Server, or DNSSEC signing operations are in use, undisclosed traffic can cause an incr…

Fix: 16.1.6 / 17.1.2+
Fix from $1,950 2025-02-05
Big Ip Access Policy Manager HIGH 7.5
CVE-2025-21091

When SNMP v1 or v2c are disabled on the BIG-IP, undisclosed requests can cause an increase in memory resource utilization. Note: Software versio…

Fix: 16.1.6 / 17.1.2+
Fix from $1,950 2025-02-05
Big Ip Access Policy Manager HIGH 8.8
CVE-2025-20029EPSS 7%

Command injection vulnerability exists in iControl REST and BIG-IP TMOS Shell (tmsh) save command, which may allow an authenticated attacker to execu…

Fix: 15.1.10.6 / 16.1.5.2+
Fix from $1,950 2025-02-05
Big Ip Access Policy Manager HIGH 7.5
CVE-2025-20045

When SIP session Application Level Gateway mode (ALG) profile with Passthru Mode enabled and SIP router ALG profile are configured on a Message Routi…

Fix: 16.1.5 / 17.1.2+
Fix from $1,950 2025-02-05
Big Ip Access Policy Manager HIGH 7.5
CVE-2025-20058

When a BIG-IP message routing profile is configured on a virtual server, undisclosed traffic can cause an increase in memory resource utilization. No…

Fix: 16.1.6 / 17.1.2+
Fix from $1,950 2025-02-05
Nginx Api Connectivity Manager MEDIUM 5.4
CVE-2024-10318

A session fixation issue was discovered in the NGINX OpenID Connect reference implementation, where a nonce was not checked at login time. This flaw …

Fix: 1.9.3 / 2.17.4+
Fix from $1,600 2024-11-06
Big Ip Access Policy Manager HIGH 7.2
CVE-2024-45844EPSS 11%

BIG-IP monitor functionality may allow an attacker to bypass access control restrictions, regardless of the port lockdown settings.  Note: Software v…

Fix: 15.1.10.5 / 16.1.5+
Fix from $1,950 2024-10-16
Big Iq Centralized Management MEDIUM 6.8
CVE-2024-47139

A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IQ Configuration utility that allows an attacker with the …

Mitigation only
Fix from $1,600 2024-10-16
Big Ip Access Policy Manager HIGH 7.5
CVE-2024-41164

When TCP profile with Multipath TCP enabled (MPTCP) is configured on a Virtual Server, undisclosed traffic along with conditions beyond the attackers…

Fix: 16.1.5+
Fix from $1,950 2024-08-14
Big Ip Access Policy Manager HIGH 7.5
CVE-2024-41727

In BIG-IP tenants running on r2000 and r4000 series hardware, or BIG-IP Virtual Edition (VEs) using Intel E810 SR-IOV NIC, undisclosed traffic can ca…

Fix: 16.1.5+
Fix from $1,950 2024-08-14
Big Ip Next Central Manager MEDIUM 5.5
CVE-2024-41719

When generating QKView of BIG-IP Next instance from the BIG-IP Next Central Manager (CM), F5 iHealth credentials will be logged in the BIG-IP Centra…

Fix: 20.2.1+
Fix from $1,600 2024-08-14
Big Ip Next Central Manager HIGH 8.8
CVE-2024-39809

The Central Manager user session refresh token does not expire when a user logs out.  Note: Software versions which have reached End of Technical Sup…

Mitigation only
Fix from $1,950 2024-08-14
Big Ip Access Policy Manager HIGH 7.5
CVE-2024-39778

When a stateless virtual server is configured on BIG-IP system with a High-Speed Bridge (HSB), undisclosed requests can cause TMM to terminate.   No…

Fix: 16.1.5+
Fix from $1,950 2024-08-14
Nginx Plus HIGH 7.5
CVE-2024-39792

When the NGINX Plus is configured to use the MQTT pre-read module, undisclosed requests can cause an increase in memory resource utilization.  Note: …

Mitigation only
Fix from $1,950 2024-08-14
Big Ip Next Central Manager MEDIUM 5.3
CVE-2024-37028

BIG-IP Next Central Manager may allow an attacker to lock out an account that has never been logged in.  Note: Software versions which have reached E…

Fix: 20.2.1+
Fix from $1,600 2024-08-14
Nginx Open Source MEDIUM 6.5
CVE-2024-32760

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 encoder instructions can cause NGINX worker processes t…

Fix: 1.26.1+
Fix from $1,600 2024-05-29