Vulnerability index

Browse CVEs

865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Nginx Open Source MEDIUM 5.3
CVE-2024-34161

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maximum Transmission Unit (MTU) o…

Fix: 1.26.1+
Fix from $1,600 2024-05-29
Nginx Open Source MEDIUM 5.3
CVE-2024-35200

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate.

Fix: 1.26.1+
Fix from $1,600 2024-05-29
Big Ip Next Central Manager MEDIUM 6.8
CVE-2024-33612

An improper certificate validation vulnerability exists in BIG-IP Next Central Manager and may allow an attacker to impersonate an Instance Provider …

Fix: 20.2.0+
Fix from $1,600 2024-05-08
Big Ip Access Policy Manager HIGH 7.5
CVE-2024-33608

When IPsec is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software …

No fix yet
Fix from $1,950 2024-05-08
Big Ip Access Policy Manager MEDIUM 6.5
CVE-2024-32761

Under certain conditions, a data leak may occur in the Traffic Management Microkernels (TMMs) of BIG-IP tenants running on VELOS and rSeries platform…

Fix: 15.1.10+
Fix from $1,600 2024-05-08
Big Ip Access Policy Manager MEDIUM 6.1
CVE-2024-33604

A reflected cross-site scripting (XSS) vulnerability exist in undisclosed page of the BIG-IP Configuration utility that allows an attacker to run Jav…

Fix: 15.1.10.4 / 16.1.4.3+
Fix from $1,600 2024-05-08
Big Ip Access Policy Manager HIGH 8.0
CVE-2024-31156

A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run Ja…

Fix: 15.1.10.4 / 16.1.4.3+
Fix from $1,950 2024-05-08
Big Ip Access Policy Manager HIGH 7.4
CVE-2024-28883

An origin validation vulnerability exists in BIG-IP APM browser network access VPN client for Windows, macOS and Linux which may allow an atta…

Fix: 7.2.4.4 / 15.1.10.3+
Fix from $1,950 2024-05-08
Big Ip Next Central Manager HIGH 7.4
CVE-2024-32049

BIG-IP Next Central Manager (CM) may allow an unauthenticated, remote attacker to obtain the BIG-IP Next LTM/WAF instance credentials.  Note: Softwa…

Fix: 20.1.0+
Fix from $1,950 2024-05-08
Big Ip Access Policy Manager MEDIUM 5.9
CVE-2024-28889

When an SSL profile with alert timeout is configured with a non-default value on a virtual server, undisclosed traffic along with conditions beyond t…

Fix: 15.1.10.4 / 16.1.4.3+
Fix from $1,600 2024-05-08
Big Ip Access Policy Manager HIGH 7.5
CVE-2024-25560

When BIG-IP AFM is licensed and provisioned, undisclosed DNS traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Soft…

Fix: 15.1.10.8 / 16.1.4+
Fix from $1,950 2024-05-08
Big Ip Next Central Manager HIGH 7.5
CVE-2024-26026EPSS 7%

An SQL injection vulnerability exists in the BIG-IP Next Central Manager API (URI).  Note: Software versions which have reached End of Technical Supp…

Fix: 20.2.0+
Fix from $1,950 2024-05-08
Big Ip Next Central Manager HIGH 7.5
CVE-2024-21793EPSS 7%

An OData injection vulnerability exists in the BIG-IP Next Central Manager API (URI).  Note: Software versions which have reached End of Technical Su…

Fix: 20.2.0+
Fix from $1,950 2024-05-08
Nginx Open Source HIGH 7.5
CVE-2024-24989

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note:…

Mitigation only
Fix from $1,950 2024-02-14
Nginx Open Source HIGH 7.5
CVE-2024-24990

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note:…

Fix: 1.25.4+
Fix from $1,950 2024-02-14
F5os A MEDIUM 5.5
CVE-2024-24966

When LDAP remote authentication is configured on F5OS, a remote user without an assigned role will be incorrectly authorized.  Note: Software version…

Fix: 1.6.0+
Fix from $1,600 2024-02-14
Big Ip Advanced Web Application Firewall HIGH 7.5
CVE-2024-23805

Undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. For the Application Visibility and Reporting module, this may o…

Fix: 15.1.10 / 16.1.4+
Fix from $1,950 2024-02-14
Big Ip Access Policy Manager HIGH 7.5
CVE-2024-23979

When SSL Client Certificate LDAP or Certificate Revocation List Distribution Point (CRLDP) authentication profile is configured on a virtual server, …

Fix: 15.1.9 / 16.1.4+
Fix from $1,950 2024-02-14
Big Ip Policy Enforcement Manager HIGH 7.5
CVE-2024-23982

When a BIG-IP PEM classification profile is configured on a UDP virtual server, undisclosed requests can cause the Traffic Management Microkernel (TM…

Fix: after 17.1.1
Fix from $1,950 2024-02-14
Big Ip Access Policy Manager HIGH 7.5
CVE-2024-24775

When a virtual server is enabled with VLAN group and SNAT listener is configured, undisclosed traffic can cause the Traffic Management Microkernel (T…

Fix: 15.1.9 / 16.1.4+
Fix from $1,950 2024-02-14
Big Ip Access Policy Manager MEDIUM 6.0
CVE-2024-23976

When running in Appliance mode, an authenticated attacker assigned the Administrator role may be able to bypass Appliance mode restrictions utilizing…

Fix: 15.1.9 / 16.1.4+
Fix from $1,600 2024-02-14
Big Ip Advanced Web Application Firewall HIGH 7.5
CVE-2024-23308

When a BIG-IP Advanced WAF or BIG-IP ASM policy with a Request Body Handling option is attached to a virtual server, undisclosed requests can cause t…

Fix: 17.1.1+
Fix from $1,950 2024-02-14
Big Ip Access Policy Manager HIGH 7.5
CVE-2024-23314

When HTTP/2 is configured on BIG-IP or BIG-IP Next SPK systems, undisclosed responses can cause the Traffic Management Microkernel (TMM) to terminate…

Fix: 15.1.9 / 16.1.4+
Fix from $1,950 2024-02-14
Big Ip Next Cloud Native Network Functions HIGH 7.1
CVE-2024-23306

A vulnerability exists in BIG-IP Next CNF and SPK systems that may allow access to undisclosed sensitive files.  Note: Software versions which have r…

Fix: 1.2.0+
Fix from $1,950 2024-02-14
F5os A MEDIUM 5.5
CVE-2024-23607

A directory traversal vulnerability exists in the F5OS QKView utility that allows an authenticated attacker to read files outside the QKView director…

Fix: 1.4.0 / 1.6.0+
Fix from $1,600 2024-02-14
Big Ip Access Policy Manager HIGH 8.7
CVE-2024-22093

When running in appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint on multi-blad…

Fix: 15.1.9 / 16.1.4+
Fix from $1,950 2024-02-14
Big Ip Advanced Web Application Firewall HIGH 7.5
CVE-2024-21789

When a BIG-IP ASM/Advanced WAF security policy is configured on a virtual server, undisclosed requests can cause an increase in memory resource utili…

Fix: 17.1.1+
Fix from $1,950 2024-02-14
Big Ip Advanced Web Application Firewall HIGH 7.5
CVE-2024-21849

When an Advanced WAF/ASM security policy and a Websockets profile are configured on a virtual server, undisclosed traffic can cause the Traffic Manag…

Fix: 16.1.4+
Fix from $1,950 2024-02-14
Big Ip Access Policy Manager HIGH 7.2
CVE-2024-22389

When BIG-IP is deployed in high availability (HA) and an iControl REST API token is updated, the change does not sync to the peer device. Note: S…

Fix: 15.1.9 / 16.1.4+
Fix from $1,950 2024-02-14
Big Ip Access Policy Manager MEDIUM 6.7
CVE-2024-21782

BIG-IP or BIG-IQ Resource Administrators and Certificate Managers who have access to the secure copy (scp) utility but do not have access to Advanced…

Fix: 15.1.9 / 16.1.4+
Fix from $1,600 2024-02-14