Vulnerability index

Browse CVEs

865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2024-34161 When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maximum Transmission Unit (MTU) o… Nginx Open Source 1.26.1+ Fix from $1,6002024-05-29 MEDIUM 5.3 CVE-2024-35200 When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate. Nginx Open Source 1.26.1+ Fix from $1,6002024-05-29 MEDIUM 6.8 CVE-2024-33612 An improper certificate validation vulnerability exists in BIG-IP Next Central Manager and may allow an attacker to impersonate an Instance Provider … Big Ip Next Central Manager 20.2.0+ Fix from $1,6002024-05-08 HIGH 7.5 CVE-2024-33608 When IPsec is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software … Big Ip Access Policy Manager No fix yet Fix from $1,9502024-05-08 MEDIUM 6.5 CVE-2024-32761 Under certain conditions, a data leak may occur in the Traffic Management Microkernels (TMMs) of BIG-IP tenants running on VELOS and rSeries platform… Big Ip Access Policy Manager 15.1.10+ Fix from $1,6002024-05-08 MEDIUM 6.1 CVE-2024-33604 A reflected cross-site scripting (XSS) vulnerability exist in undisclosed page of the BIG-IP Configuration utility that allows an attacker to run Jav… Big Ip Access Policy Manager 15.1.10.4 / 16.1.4.3+ Fix from $1,6002024-05-08 HIGH 8.0 CVE-2024-31156 A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run Ja… Big Ip Access Policy Manager 15.1.10.4 / 16.1.4.3+ Fix from $1,9502024-05-08 HIGH 7.4 CVE-2024-28883 An origin validation vulnerability exists in BIG-IP APM browser network access VPN client for Windows, macOS and Linux which may allow an atta… Big Ip Access Policy Manager 7.2.4.4 / 15.1.10.3+ Fix from $1,9502024-05-08 HIGH 7.4 CVE-2024-32049 BIG-IP Next Central Manager (CM) may allow an unauthenticated, remote attacker to obtain the BIG-IP Next LTM/WAF instance credentials.  Note: Softwa… Big Ip Next Central Manager 20.1.0+ Fix from $1,9502024-05-08 MEDIUM 5.9 CVE-2024-28889 When an SSL profile with alert timeout is configured with a non-default value on a virtual server, undisclosed traffic along with conditions beyond t… Big Ip Access Policy Manager 15.1.10.4 / 16.1.4.3+ Fix from $1,6002024-05-08 HIGH 7.5 CVE-2024-25560 When BIG-IP AFM is licensed and provisioned, undisclosed DNS traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Soft… Big Ip Access Policy Manager 15.1.10.8 / 16.1.4+ Fix from $1,9502024-05-08 HIGH 7.5 CVE-2024-26026EPSS 7% An SQL injection vulnerability exists in the BIG-IP Next Central Manager API (URI).  Note: Software versions which have reached End of Technical Supp… Big Ip Next Central Manager 20.2.0+ Fix from $1,9502024-05-08 HIGH 7.5 CVE-2024-21793EPSS 7% An OData injection vulnerability exists in the BIG-IP Next Central Manager API (URI).  Note: Software versions which have reached End of Technical Su… Big Ip Next Central Manager 20.2.0+ Fix from $1,9502024-05-08 HIGH 7.5 CVE-2024-24989 When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note:… Nginx Open Source Mitigation only Fix from $1,9502024-02-14 HIGH 7.5 CVE-2024-24990 When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note:… Nginx Open Source 1.25.4+ Fix from $1,9502024-02-14 MEDIUM 5.5 CVE-2024-24966 When LDAP remote authentication is configured on F5OS, a remote user without an assigned role will be incorrectly authorized.  Note: Software version… F5os A 1.6.0+ Fix from $1,6002024-02-14 HIGH 7.5 CVE-2024-23805 Undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. For the Application Visibility and Reporting module, this may o… Big Ip Advanced Web Application Firewall 15.1.10 / 16.1.4+ Fix from $1,9502024-02-14 HIGH 7.5 CVE-2024-23979 When SSL Client Certificate LDAP or Certificate Revocation List Distribution Point (CRLDP) authentication profile is configured on a virtual server, … Big Ip Access Policy Manager 15.1.9 / 16.1.4+ Fix from $1,9502024-02-14 HIGH 7.5 CVE-2024-23982 When a BIG-IP PEM classification profile is configured on a UDP virtual server, undisclosed requests can cause the Traffic Management Microkernel (TM… Big Ip Policy Enforcement Manager after 17.1.1 Fix from $1,9502024-02-14 HIGH 7.5 CVE-2024-24775 When a virtual server is enabled with VLAN group and SNAT listener is configured, undisclosed traffic can cause the Traffic Management Microkernel (T… Big Ip Access Policy Manager 15.1.9 / 16.1.4+ Fix from $1,9502024-02-14 MEDIUM 6.0 CVE-2024-23976 When running in Appliance mode, an authenticated attacker assigned the Administrator role may be able to bypass Appliance mode restrictions utilizing… Big Ip Access Policy Manager 15.1.9 / 16.1.4+ Fix from $1,6002024-02-14 HIGH 7.5 CVE-2024-23308 When a BIG-IP Advanced WAF or BIG-IP ASM policy with a Request Body Handling option is attached to a virtual server, undisclosed requests can cause t… Big Ip Advanced Web Application Firewall 17.1.1+ Fix from $1,9502024-02-14 HIGH 7.5 CVE-2024-23314 When HTTP/2 is configured on BIG-IP or BIG-IP Next SPK systems, undisclosed responses can cause the Traffic Management Microkernel (TMM) to terminate… Big Ip Access Policy Manager 15.1.9 / 16.1.4+ Fix from $1,9502024-02-14 HIGH 7.1 CVE-2024-23306 A vulnerability exists in BIG-IP Next CNF and SPK systems that may allow access to undisclosed sensitive files.  Note: Software versions which have r… Big Ip Next Cloud Native Network Functions 1.2.0+ Fix from $1,9502024-02-14 MEDIUM 5.5 CVE-2024-23607 A directory traversal vulnerability exists in the F5OS QKView utility that allows an authenticated attacker to read files outside the QKView director… F5os A 1.4.0 / 1.6.0+ Fix from $1,6002024-02-14 HIGH 8.7 CVE-2024-22093 When running in appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint on multi-blad… Big Ip Access Policy Manager 15.1.9 / 16.1.4+ Fix from $1,9502024-02-14 HIGH 7.5 CVE-2024-21789 When a BIG-IP ASM/Advanced WAF security policy is configured on a virtual server, undisclosed requests can cause an increase in memory resource utili… Big Ip Advanced Web Application Firewall 17.1.1+ Fix from $1,9502024-02-14 HIGH 7.5 CVE-2024-21849 When an Advanced WAF/ASM security policy and a Websockets profile are configured on a virtual server, undisclosed traffic can cause the Traffic Manag… Big Ip Advanced Web Application Firewall 16.1.4+ Fix from $1,9502024-02-14 HIGH 7.2 CVE-2024-22389 When BIG-IP is deployed in high availability (HA) and an iControl REST API token is updated, the change does not sync to the peer device. Note: S… Big Ip Access Policy Manager 15.1.9 / 16.1.4+ Fix from $1,9502024-02-14 MEDIUM 6.7 CVE-2024-21782 BIG-IP or BIG-IQ Resource Administrators and Certificate Managers who have access to the secure copy (scp) utility but do not have access to Advanced… Big Ip Access Policy Manager 15.1.9 / 16.1.4+ Fix from $1,6002024-02-14