Vulnerability index

Browse CVEs

865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2025-58424 On BIG-IP systems, undisclosed traffic can cause data corruption and unauthorized data modification in protocols which do not have message integrity … Big Ip Access Policy Manager 15.1.10.8 / 16.1.6+ Fix from $1,6002025-10-15 HIGH 7.5 CVE-2025-55036 When BIG-IP SSL Orchestrator explicit forward proxy is configured on a virtual server and the proxy connect feature is enabled, undisclosed traffic m… Big Ip Ssl Orchestrator 15.1.10.8 / 16.1.6+ Fix from $1,9502025-10-15 HIGH 7.5 CVE-2025-55669 When the BIG-IP Advanced WAF and ASM security policy and a server-side HTTP/2 profile are configured on a virtual server, undisclosed traffic can cau… Big Ip Application Security Manager 16.1.6+ Fix from $1,9502025-10-15 MEDIUM 6.5 CVE-2025-55670 On BIG-IP Next CNF, BIG-IP Next SPK, and BIG-IP Next for Kubernetes systems, repeated undisclosed API calls can cause the Traffic Management Microker… Big Ip Next Cloud Native Network Functions after 1.9.2 Fix from $1,6002025-10-15 HIGH 7.5 CVE-2025-54854 When a BIG-IP APM OAuth access profile (Resource Server or Resource Client) is configured on a virtual server, undisclosed traffic can cause the apmd… Big Ip Access Policy Manager 15.1.10.8 / 16.1.6.1+ Fix from $1,9502025-10-15 HIGH 7.5 CVE-2025-54858 When a BIG-IP Advanced WAF or BIG-IP ASM Security Policy is configured with a JSON content profile that has a malformed JSON schema, and the security… Big Ip Advanced Web Application Firewall 15.1.10.8 / 16.1.6.1+ Fix from $1,9502025-10-15 HIGH 7.5 CVE-2025-54479 When a classification profile is configured on a virtual server without an HTTP or HTTP/2 profile, undisclosed requests can cause the Traffic Managem… Big Ip Next Cloud Native Network Functions 15.1.10.8 / 16.1.6.1+ Fix from $1,9502025-10-15 MEDIUM 6.5 CVE-2025-54805 When an iRule is configured on a virtual server via the declarative API, upon re-instantiation, the cleanup process can cause an increase in the Traf… Big Ip Next Cloud Native Network Functions after 1.9.2 Fix from $1,6002025-10-15 CRITICAL 9.8 CVE-2025-53521 KEV When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).   Note: Softw… Big Ip Access Policy Manager 15.1.10.8 / 16.1.6.1+ Fix from $2,3002025-10-15 HIGH 8.7 CVE-2025-53868 When running in Appliance mode, a highly privileged authenticated attacker with access to SCP and SFTP may be able to bypass Appliance mode restricti… Big Ip Access Policy Manager 15.1.10.8 / 16.1.6.1+ Fix from $1,9502025-10-15 HIGH 7.5 CVE-2025-48008 When a TCP profile with Multipath TCP (MPTCP) enabled is configured on a virtual server, undisclosed traffic along with conditions beyond the attacke… Big Ip Next Cloud Native Network Functions 15.1.10.8 / 16.1.6+ Fix from $1,9502025-10-15 HIGH 7.5 CVE-2025-53474 When an iRule using an ILX::call command is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to… Big Ip Access Policy Manager 15.1.1.0.8 / 16.1.6.1+ Fix from $1,9502025-10-15 HIGH 7.5 CVE-2025-53856 When a virtual server, network address translation (NAT) object, or secure network address translation (SNAT) object uses the embedded Packet Velocit… Big Ip Access Policy Manager 15.1.10.8 / 16.1.6.1+ Fix from $1,9502025-10-15 HIGH 7.5 CVE-2025-41430 When BIG-IP SSL Orchestrator is enabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versi… Big Ip Ssl Orchestrator 16.1.4 / 17.1.3+ Fix from $1,9502025-10-15 HIGH 7.5 CVE-2025-46706 When an iRule containing the HTTP::respond command is configured on a virtual server, undisclosed requests can cause an increase in memory resource u… Big Ip Next Cloud Native Network Functions 16.1.6 / 17.1.2.2+ Fix from $1,9502025-10-15 MEDIUM 6.5 CVE-2025-47148 When the BIG-IP system is configured as both a Security Assertion Markup Language (SAML) service provider (SP) and Identity Provider (IdP), with sing… Big Ip Access Policy Manager 15.1.10.8 / 16.1.6.1+ Fix from $1,6002025-10-15 MEDIUM 6.5 CVE-2025-47150 When SNMP is configured on F5OS Appliance and Chassis systems, undisclosed requests can cause an increase in SNMP memory resource utilization.  Note:… F5os A 1.5.3 / 1.6.4+ Fix from $1,6002025-10-15 HIGH 7.4 CVE-2025-54809 F5 Access for Android before version 3.1.2 which uses HTTPS does not verify the remote endpoint identity. Note: Software versions which have rea… F5 Access 3.1.2+ Fix from $1,9502025-08-13 MEDIUM 5.3 CVE-2025-54500 An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to break the max concurrent streams… Big Ip Access Policy Manager 15.1.10.8 / 16.1.6.1+ Fix from $1,6002025-08-13 HIGH 7.5 CVE-2025-52585 When a BIG-IP LTM Client SSL profile is configured on a virtual server with SSL Forward Proxy enabled and Anonymous Diffie-Hellman (ADH) ciphers enab… Big Ip Access Policy Manager 15.1.10.8 / 16.1.6+ Fix from $1,9502025-08-13 HIGH 7.5 CVE-2025-46405 When Network Access is configured on a BIG-IP APM virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate… Big Ip Access Policy Manager 15.1.10.8 / 16.1.6+ Fix from $1,9502025-08-13 HIGH 7.3 CVE-2025-48500 A missing file integrity check vulnerability exists on MacOS F5 VPN browser client installer that may allow a local, authenticated attacker with acce… Big Ip Access Policy Manager 15.1.10.8 / 16.1.6.1+ Fix from $1,9502025-08-13 HIGH 8.8 CVE-2025-46265 On F5OS, an improper authorization vulnerability exists where remotely authenticated users (LDAP, RADIUS, TACACS+) may be authorized with higher priv… F5os A after 1.6.2 Fix from $1,9502025-05-07 HIGH 7.5 CVE-2025-36557 When an HTTP profile with the Enforce RFC Compliance option is configured on a virtual server, undisclosed requests can cause the Traffic Management … Big Ip Access Policy Manager 16.1.5 / 17.1.2+ Fix from $1,9502025-05-07 HIGH 7.5 CVE-2025-41399 When a Stream Control Transmission Protocol (SCTP) profile is configured on a virtual server, undisclosed requests can cause an increase in memory re… Big Ip Access Policy Manager 15.1.9 / 16.1.4+ Fix from $1,9502025-05-07 HIGH 7.5 CVE-2025-41414 When HTTP/2 client and server profile is configured on a virtual server, undisclosed requests can cause TMM to terminate.  Note: Software versio… Big Ip Access Policy Manager 16.1.5 / 17.1.2+ Fix from $1,9502025-05-07 HIGH 7.5 CVE-2025-41431 When connection mirroring is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate in … Big Ip Access Policy Manager Mitigation only Fix from $1,9502025-05-07 HIGH 7.5 CVE-2025-41433 When a Session Initiation Protocol (SIP) message routing framework (MRF) application layer gateway (ALG) profile is configured on a Message Routing v… Big Ip Access Policy Manager 16.1.5 / 17.1.2+ Fix from $1,9502025-05-07 MEDIUM 6.0 CVE-2025-43878 When running in Appliance mode, an authenticated attacker assigned the Administrator or Resource Administrator role may be able to bypass Appliance m… F5os A 1.8.0+ Fix from $1,6002025-05-07 HIGH 8.1 CVE-2025-36546 On an F5OS system, if the root user had previously configured the system to allow login via SSH key-based authentication, and then enabled Appliance … F5os A 1.5.3+ Fix from $1,9502025-05-07