Vulnerability index

Browse CVEs

865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Big Ip Access Policy Manager MEDIUM 6.1
CVE-2023-27378

Multiple reflected cross-site scripting (XSS) vulnerabilities exist in undisclosed pages of the BIG-IP Configuration utility which allow an attacker …

Fix: 14.1.5.4 / 15.1.8.2+
Fix from $1,600 2023-05-03
Big Ip Access Policy Manager MEDIUM 5.9
CVE-2023-24461

An improper certificate validation vulnerability exists in the BIG-IP Edge Client for Windows and macOS and may allow an attacker to impersonate a BI…

Fix: 7.2.4.1+
Fix from $1,600 2023-05-03
Big Ip Access Policy Manager MEDIUM 5.3
CVE-2023-24594

When an SSL profile is configured on a Virtual Server, undisclosed traffic can cause an increase in CPU or SSL accelerator resource utilization.   N…

Mitigation only
Fix from $1,600 2023-05-03
Big Ip Access Policy Manager MEDIUM 5.9
CVE-2023-22372

In the pre connection stage, an improper enforcement of message integrity vulnerability exists in BIG-IP Edge Client for Windows and Mac OS.  Note: S…

Fix: 7.2.4.1+
Fix from $1,600 2023-05-03
Njs HIGH 7.5
CVE-2023-27727

Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_function_frame at src/njs_function.h.

No fix yet
Fix from $1,950 2023-04-09
Njs HIGH 7.5
CVE-2023-27728

Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_dump_is_recursive at src/njs_vmcode.c.

Patch available
Fix from $1,950 2023-04-09
Njs HIGH 7.5
CVE-2023-27729

Nginx NJS v0.7.10 was discovered to contain an illegal memcpy via the function njs_vmcode_return at src/njs_vmcode.c.

Patch available
Fix from $1,950 2023-04-09
Njs HIGH 7.5
CVE-2023-27730

Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_lvlhsh_find at src/njs_lvlhsh.c.

Patch available
Fix from $1,950 2023-04-09
Njs CRITICAL 9.8
CVE-2020-19692

Buffer Overflow vulnerabilty found in Nginx NJS v.0feca92 allows a remote attacker to execute arbitrary code via the njs_module_read in the njs_modul…

Fix: 0.3.4+
Fix from $2,300 2023-04-04
Njs CRITICAL 9.8
CVE-2020-19695

Buffer Overflow found in Nginx NJS allows a remote attacker to execute arbitrary code via the njs_object_property parameter of the njs/njs_vm.c funct…

Fix: 0.3.4+
Fix from $2,300 2023-04-04
Nginx Agent MEDIUM 5.5
CVE-2023-1550

Insertion of Sensitive Information into log file vulnerability in NGINX Agent. NGINX Agent version 2.0 before 2.23.3 inserts sensitive information in…

Fix: 2.9.0 / 2.23.3+
Fix from $1,600 2023-03-29
Big Ip Access Policy Manager HIGH 8.5
CVE-2023-22374EPSS 73%

A format string vulnerability exists in iControl SOAP that allows an authenticated attacker to crash the iControl SOAP CGI process or, potentially ex…

Fix: after 16.1.3
Fix from $1,950 2023-02-01
Big Ip Access Policy Manager HIGH 7.8
CVE-2023-22358

In versions beginning with 7.2.2 to before 7.2.3.1, a DLL hijacking vulnerability exists in the BIG-IP Edge Client Windows Installer. Note: Software…

Fix: 7.2.3.1 / 17.0.0.2+
Fix from $1,950 2023-02-01
F5os A HIGH 7.8
CVE-2023-22657

On F5OS-A beginning in version 1.2.0 to before 1.3.0 and F5OS-C beginning in version 1.3.0 to before 1.5.0, processing F5OS tenant file names may all…

Fix: 1.3.0 / 1.5.0+
Fix from $1,950 2023-02-01
Big Ip Access Policy Manager HIGH 7.5
CVE-2023-22340

On BIG-IP versions 16.1.x before 16.1.3.3, 15.1.x before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a SIP profile is configured…

Fix: 14.1.5.3 / 15.1.8+
Fix from $1,950 2023-02-01
Big Ip Access Policy Manager HIGH 7.5
CVE-2023-22341

On version 14.1.x before 14.1.5.3, and all versions of 13.1.x, when the BIG-IP APM system is configured with all the following elements, undisclosed …

Fix: 14.1.5.3+
Fix from $1,950 2023-02-01
Big Ip Access Policy Manager HIGH 7.5
CVE-2023-22422

On BIG-IP versions 17.0.x before 17.0.0.2 and 16.1.x before 16.1.3.3, when a HTTP profile with the non-default Enforcement options of Enforce HTTP Co…

Fix: 16.1.3.3 / 17.0.0.2+
Fix from $1,950 2023-02-01
Big Ip Access Policy Manager HIGH 7.5
CVE-2023-22664

On BIG-IP versions 17.0.x before 17.0.0.2 and 16.1.x before 16.1.3.3, and BIG-IP SPK starting in version 1.6.0, when a client-side HTTP/2 profile and…

Fix: 16.1.3.3 / 17.0.0.2+
Fix from $1,950 2023-02-01
Big Ip Domain Name System HIGH 7.5
CVE-2023-22839

On BIG-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all version of 13.1.x, when a …

Fix: 14.1.5.3 / 15.1.7+
Fix from $1,950 2023-02-01
Big Ip Access Policy Manager HIGH 7.5
CVE-2023-22842

On BIG-IP versions 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a SIP profile is configur…

Fix: 14.1.5.3 / 15.1.8.1+
Fix from $1,950 2023-02-01
Big Ip Advanced Web Application Firewall HIGH 7.5
CVE-2023-23552

On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.0 before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a BIG-IP A…

Fix: 14.1.5.3 / 15.1.8+
Fix from $1,950 2023-02-01
Big Ip Access Policy Manager HIGH 7.5
CVE-2023-23555

On BIG-IP Virtual Edition versions 15.1x beginning in 15.1.4 to before 15.1.8 and 14.1.x beginning in 14.1.5 to before 14.1.5.3, and BIG-IP SPK begin…

Fix: 14.1.5.3 / 15.1.8+
Fix from $1,950 2023-02-01
Big Ip Access Policy Manager MEDIUM 6.1
CVE-2023-22418

On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.7, 14.1.x before 14.1.5.3, and all versions of 13.1.x, an open redirec…

Fix: 14.1.5.3 / 15.1.7+
Fix from $1,600 2023-02-01
Big Ip Advanced Firewall Manager HIGH 7.5
CVE-2023-22281

On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a BIG-IP A…

Fix: 14.1.5.3 / 15.1.8+
Fix from $1,950 2023-02-01
Big Ip Access Policy Manager HIGH 7.5
CVE-2023-22323

In BIP-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when O…

Fix: 14.1.5.3 / 15.1.8.1+
Fix from $1,950 2023-02-01
Big Ip Access Policy Manager MEDIUM 6.5
CVE-2023-22283

On versions beginning in 7.1.5 to before 7.2.3.1, a DLL hijacking vulnerability exists in the BIG-IP Edge Client for Windows. User interaction and ad…

Fix: 7.2.3.1 / 17.0.0.2+
Fix from $1,600 2023-02-01
Big Ip Access Policy Manager MEDIUM 5.9
CVE-2023-22302

In BIG-IP versions 17.0.x before 17.0.0.2, and 16.1.x beginning in 16.1.2.2 to before 16.1.3.3, when an HTTP profile is configured on a virtual serve…

Fix: 16.1.3.3 / 17.0.0.2+
Fix from $1,600 2023-02-01
Big Iq Centralized Management HIGH 8.8
CVE-2022-41622EPSS 88%

In all versions,  BIG-IP and BIG-IQ are vulnerable to cross-site request forgery (CSRF) attacks through iControl SOAP.   Note: Software versions wh…

Fix: after 16.1.3
Fix from $1,950 2022-12-07
Big Ip Access Policy Manager HIGH 8.7
CVE-2022-41800EPSS 66%

In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode…

Fix: after 17.0.0
Fix from $1,950 2022-12-07
Njs CRITICAL 9.8
CVE-2022-43286

Nginx NJS v0.7.2 was discovered to contain a heap-use-after-free bug caused by illegal memory copy in the function njs_json_parse_iterator_call at nj…

Patch available
Fix from $2,300 2022-10-28