Vulnerability index

Browse CVEs

865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Big Ip Advanced Firewall Manager HIGH 7.5
CVE-2024-21763

When BIG-IP AFM Device DoS or DoS profile is configured with NXDOMAIN attack vector and bad actor detection, undisclosed queries can cause the Traffi…

Fix: 17.1.1+
Fix from $1,950 2024-02-14
Big Ip Advanced Firewall Manager HIGH 7.5
CVE-2024-21771

For unspecified traffic patterns, BIG-IP AFM IPS engine may spend an excessive amount of time matching the traffic against signatures, resulting in T…

Fix: 15.1.9 / 16.1.4+
Fix from $1,950 2024-02-14
Big Ip Next HIGH 7.5
CVE-2023-45886

The BGP daemon (bgpd) in IP Infusion ZebOS through 7.10.6 allow remote attackers to cause a denial of service by sending crafted BGP update messages …

Fix: after 17.1.1
Fix from $1,950 2023-11-21
Big Ip Access Policy Manager CRITICAL 9.8
CVE-2023-46747 KEVEPSS 97%

Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the manag…

Fix: after 17.1.1
Fix from $2,300 2023-10-26
Big Ip Access Policy Manager HIGH 8.8
CVE-2023-46748 KEV

An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may allow an authenticated attacker with network acce…

Fix: after 17.1.1
Fix from $1,950 2023-10-26
Big Ip Access Policy Manager HIGH 7.8
CVE-2023-5450

An insufficient verification of data vulnerability exists in BIG-IP Edge Client Installer on macOS that may allow an attacker elevation of privileges…

Fix: 7.2.4.5 / 15.1.10+
Fix from $1,950 2023-10-10
Big Ip Next Service Proxy For Kubernetes HIGH 7.4
CVE-2023-45226

The BIG-IP SPK TMM (Traffic Management Module) f5-debug-sidecar and f5-debug-sshd containers contains hardcoded credentials that may allow an attacke…

Mitigation only
Fix from $1,950 2023-10-10
Big Ip Access Policy Manager CRITICAL 9.9
CVE-2023-41373

A directory traversal vulnerability exists in the BIG-IP Configuration Utility that may allow an authenticated attacker to execute commands on the BI…

Fix: 14.1.5.6 / 15.1.10.2+
Fix from $2,300 2023-10-10
Big Ip Access Policy Manager HIGH 8.7
CVE-2023-43746

When running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing BI…

Fix: 15.1.9 / 16.1.4+
Fix from $1,950 2023-10-10
Big Ip Access Policy Manager HIGH 7.8
CVE-2023-43611

The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installation process.  This vulnerabilit…

Fix: 7.2.4.4 / 15.1.9+
Fix from $1,950 2023-10-10
Big Ip Access Policy Manager HIGH 7.5
CVE-2023-41085

When IPSec is configured on a Virtual Server, undisclosed traffic can cause TMM to terminate.  Note: Software versions which have reached End of Tec…

Fix: 15.1.9 / 16.1.4+
Fix from $1,950 2023-10-10
Big Ip Access Policy Manager HIGH 7.2
CVE-2023-42768

When a non-admin user has been assigned an administrator role via an iControl REST PUT request and later the user's role is reverted back to a non-ad…

Fix: 15.1.9 / 16.1.4+
Fix from $1,950 2023-10-10
Big Ip Access Policy Manager MEDIUM 6.5
CVE-2023-41964

The BIG-IP and BIG-IQ systems do not encrypt some sensitive information written to Database (DB) variables.  Note: Software versions which have reac…

Fix: 15.1.9 / 16.1.4+
Fix from $1,600 2023-10-10
Big Ip Domain Name System MEDIUM 5.5
CVE-2023-41253

When on BIG-IP DNS or BIG-IP LTM enabled with DNS Services License, and a TSIG key is created, it is logged in plaintext in the audit log.  Note: Sof…

Fix: 15.1.9 / 16.1.4+
Fix from $1,600 2023-10-10
Big Iq Centralized Management MEDIUM 5.5
CVE-2023-43485

When TACACS+ audit forwarding is configured on BIG-IP or BIG-IQ system, sharedsecret is logged in plaintext in the audit log.  Note: Software version…

Fix: 8.2.0.1.0.13.97-eng / 8.3.0.0.12.118-eng+
Fix from $1,600 2023-10-10
Big Ip Access Policy Manager HIGH 8.1
CVE-2023-40537

An authenticated user's session cookie may remain valid for a limited time after logging out from the BIG-IP Configuration utility on a multi-blade V…

Fix: 15.1.9 / 16.1.4+
Fix from $1,950 2023-10-10
Big Ip Access Policy Manager HIGH 7.5
CVE-2023-40534

When a client-side HTTP/2 profile and the HTTP MRF Router option are enabled for a virtual server, and an iRule using the HTTP_REQUEST event or Local…

Fix: 16.1.4.1+
Fix from $1,950 2023-10-10
Big Ip Access Policy Manager HIGH 7.5
CVE-2023-40542

When TCP Verified Accept is enabled on a TCP profile that is configured on a Virtual Server, undisclosed requests can cause an increase in memory res…

Fix: 15.1.9 / 16.1.4+
Fix from $1,950 2023-10-10
Big Ip Access Policy Manager HIGH 8.2
CVE-2023-43125

BIG-IP APM clients may send IP traffic outside of the VPN tunnel.  Note: Software versions which have reached End of Technical Support (EoTS) are not…

Fix: after 16.1.4
Fix from $1,950 2023-09-27
Big Ip Access Policy Manager HIGH 7.1
CVE-2023-43124

BIG-IP APM clients may send IP traffic outside of the VPN tunnel.  Note: Software versions which have reached End of Technical Support (EoTS) are not…

Fix: after 16.1.4
Fix from $1,950 2023-09-27
Access Policy Manager Clients HIGH 7.8
CVE-2023-38418

The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installation process.  Note: Software ve…

Fix: 7.2.4.3+
Fix from $1,950 2023-08-02
Big Ip Access Policy Manager MEDIUM 6.1
CVE-2023-38138

A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which allows an attacker to ru…

Fix: 14.1.5.5 / 15.1.9.1+
Fix from $1,600 2023-08-02
Big Ip Access Policy Manager MEDIUM 6.1
CVE-2023-3470

Specific F5 BIG-IP platforms with Cavium Nitrox FIPS HSM cards generate a deterministic password for the Crypto User account.  The predictable nature…

Fix: 13.1.4 / 14.1.4+
Fix from $1,600 2023-08-02
Access Policy Manager Clients MEDIUM 5.5
CVE-2023-36858

An insufficient verification of data vulnerability exists in BIG-IP Edge Client for Windows and macOS that may allow an attacker to modify its config…

Fix: 7.2.4.3+
Fix from $1,600 2023-08-02
Big Ip Access Policy Manager MEDIUM 5.4
CVE-2023-38423

A cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScrip…

Fix: 14.1.5.5 / 15.1.9.1+
Fix from $1,600 2023-08-02
Big Ip Domain Name System HIGH 8.8
CVE-2023-28742

When DNS is provisioned, an authenticated remote command execution vulnerability exists in DNS iQuery mesh. Note: Software versions which have r…

Fix: 14.1.5.4 / 15.1.8.2+
Fix from $1,950 2023-05-03
Big Ip Access Policy Manager HIGH 7.5
CVE-2023-29163

When UDP profile with idle timeout set to immediate or the value 0 is configured on a virtual server, undisclosed traffic can cause TMM to terminate.…

Fix: 14.1.5.4 / 15.1.8.2+
Fix from $1,950 2023-05-03
Nginx Api Connectivity Manager HIGH 7.1
CVE-2023-28724

NGINX Management Suite default file permissions are set such that an authenticated attacker may be able to modify sensitive files on NGINX Instance M…

Fix: 1.3.0 / 1.5.0+
Fix from $1,950 2023-05-03
Big Iq Centralized Management MEDIUM 5.4
CVE-2023-29240

An authenticated attacker granted a Viewer or Auditor role on a BIG-IQ can upload arbitrary files using an undisclosed iControl REST endpoint.  Note:…

Fix: 8.3.0+
Fix from $1,600 2023-05-03
Nginx Api Connectivity Manager HIGH 8.1
CVE-2023-28656

NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned environment.   Note: So…

Fix: 1.3.0 / 1.5.0+
Fix from $1,950 2023-05-03