Vulnerability index

Browse CVEs

865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2024-21763 When BIG-IP AFM Device DoS or DoS profile is configured with NXDOMAIN attack vector and bad actor detection, undisclosed queries can cause the Traffi… Big Ip Advanced Firewall Manager 17.1.1+ Fix from $1,9502024-02-14 HIGH 7.5 CVE-2024-21771 For unspecified traffic patterns, BIG-IP AFM IPS engine may spend an excessive amount of time matching the traffic against signatures, resulting in T… Big Ip Advanced Firewall Manager 15.1.9 / 16.1.4+ Fix from $1,9502024-02-14 HIGH 7.5 CVE-2023-45886 The BGP daemon (bgpd) in IP Infusion ZebOS through 7.10.6 allow remote attackers to cause a denial of service by sending crafted BGP update messages … Big Ip Next after 17.1.1 Fix from $1,9502023-11-21 CRITICAL 9.8 CVE-2023-46747 KEVEPSS 97% Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the manag… Big Ip Access Policy Manager after 17.1.1 Fix from $2,3002023-10-26 HIGH 8.8 CVE-2023-46748 KEV An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may allow an authenticated attacker with network acce… Big Ip Access Policy Manager after 17.1.1 Fix from $1,9502023-10-26 HIGH 7.8 CVE-2023-5450 An insufficient verification of data vulnerability exists in BIG-IP Edge Client Installer on macOS that may allow an attacker elevation of privileges… Big Ip Access Policy Manager 7.2.4.5 / 15.1.10+ Fix from $1,9502023-10-10 HIGH 7.4 CVE-2023-45226 The BIG-IP SPK TMM (Traffic Management Module) f5-debug-sidecar and f5-debug-sshd containers contains hardcoded credentials that may allow an attacke… Big Ip Next Service Proxy For Kubernetes Mitigation only Fix from $1,9502023-10-10 CRITICAL 9.9 CVE-2023-41373 A directory traversal vulnerability exists in the BIG-IP Configuration Utility that may allow an authenticated attacker to execute commands on the BI… Big Ip Access Policy Manager 14.1.5.6 / 15.1.10.2+ Fix from $2,3002023-10-10 HIGH 8.7 CVE-2023-43746 When running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing BI… Big Ip Access Policy Manager 15.1.9 / 16.1.4+ Fix from $1,9502023-10-10 HIGH 7.8 CVE-2023-43611 The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installation process.  This vulnerabilit… Big Ip Access Policy Manager 7.2.4.4 / 15.1.9+ Fix from $1,9502023-10-10 HIGH 7.5 CVE-2023-41085 When IPSec is configured on a Virtual Server, undisclosed traffic can cause TMM to terminate.  Note: Software versions which have reached End of Tec… Big Ip Access Policy Manager 15.1.9 / 16.1.4+ Fix from $1,9502023-10-10 HIGH 7.2 CVE-2023-42768 When a non-admin user has been assigned an administrator role via an iControl REST PUT request and later the user's role is reverted back to a non-ad… Big Ip Access Policy Manager 15.1.9 / 16.1.4+ Fix from $1,9502023-10-10 MEDIUM 6.5 CVE-2023-41964 The BIG-IP and BIG-IQ systems do not encrypt some sensitive information written to Database (DB) variables.  Note: Software versions which have reac… Big Ip Access Policy Manager 15.1.9 / 16.1.4+ Fix from $1,6002023-10-10 MEDIUM 5.5 CVE-2023-41253 When on BIG-IP DNS or BIG-IP LTM enabled with DNS Services License, and a TSIG key is created, it is logged in plaintext in the audit log.  Note: Sof… Big Ip Domain Name System 15.1.9 / 16.1.4+ Fix from $1,6002023-10-10 MEDIUM 5.5 CVE-2023-43485 When TACACS+ audit forwarding is configured on BIG-IP or BIG-IQ system, sharedsecret is logged in plaintext in the audit log.  Note: Software version… Big Iq Centralized Management 8.2.0.1.0.13.97-eng / 8.3.0.0.12.118-eng+ Fix from $1,6002023-10-10 HIGH 8.1 CVE-2023-40537 An authenticated user's session cookie may remain valid for a limited time after logging out from the BIG-IP Configuration utility on a multi-blade V… Big Ip Access Policy Manager 15.1.9 / 16.1.4+ Fix from $1,9502023-10-10 HIGH 7.5 CVE-2023-40534 When a client-side HTTP/2 profile and the HTTP MRF Router option are enabled for a virtual server, and an iRule using the HTTP_REQUEST event or Local… Big Ip Access Policy Manager 16.1.4.1+ Fix from $1,9502023-10-10 HIGH 7.5 CVE-2023-40542 When TCP Verified Accept is enabled on a TCP profile that is configured on a Virtual Server, undisclosed requests can cause an increase in memory res… Big Ip Access Policy Manager 15.1.9 / 16.1.4+ Fix from $1,9502023-10-10 HIGH 8.2 CVE-2023-43125 BIG-IP APM clients may send IP traffic outside of the VPN tunnel.  Note: Software versions which have reached End of Technical Support (EoTS) are not… Big Ip Access Policy Manager after 16.1.4 Fix from $1,9502023-09-27 HIGH 7.1 CVE-2023-43124 BIG-IP APM clients may send IP traffic outside of the VPN tunnel.  Note: Software versions which have reached End of Technical Support (EoTS) are not… Big Ip Access Policy Manager after 16.1.4 Fix from $1,9502023-09-27 HIGH 7.8 CVE-2023-38418 The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installation process.  Note: Software ve… Access Policy Manager Clients 7.2.4.3+ Fix from $1,9502023-08-02 MEDIUM 6.1 CVE-2023-38138 A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which allows an attacker to ru… Big Ip Access Policy Manager 14.1.5.5 / 15.1.9.1+ Fix from $1,6002023-08-02 MEDIUM 6.1 CVE-2023-3470 Specific F5 BIG-IP platforms with Cavium Nitrox FIPS HSM cards generate a deterministic password for the Crypto User account.  The predictable nature… Big Ip Access Policy Manager 13.1.4 / 14.1.4+ Fix from $1,6002023-08-02 MEDIUM 5.5 CVE-2023-36858 An insufficient verification of data vulnerability exists in BIG-IP Edge Client for Windows and macOS that may allow an attacker to modify its config… Access Policy Manager Clients 7.2.4.3+ Fix from $1,6002023-08-02 MEDIUM 5.4 CVE-2023-38423 A cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScrip… Big Ip Access Policy Manager 14.1.5.5 / 15.1.9.1+ Fix from $1,6002023-08-02 HIGH 8.8 CVE-2023-28742 When DNS is provisioned, an authenticated remote command execution vulnerability exists in DNS iQuery mesh. Note: Software versions which have r… Big Ip Domain Name System 14.1.5.4 / 15.1.8.2+ Fix from $1,9502023-05-03 HIGH 7.5 CVE-2023-29163 When UDP profile with idle timeout set to immediate or the value 0 is configured on a virtual server, undisclosed traffic can cause TMM to terminate.… Big Ip Access Policy Manager 14.1.5.4 / 15.1.8.2+ Fix from $1,9502023-05-03 HIGH 7.1 CVE-2023-28724 NGINX Management Suite default file permissions are set such that an authenticated attacker may be able to modify sensitive files on NGINX Instance M… Nginx Api Connectivity Manager 1.3.0 / 1.5.0+ Fix from $1,9502023-05-03 MEDIUM 5.4 CVE-2023-29240 An authenticated attacker granted a Viewer or Auditor role on a BIG-IQ can upload arbitrary files using an undisclosed iControl REST endpoint.  Note:… Big Iq Centralized Management 8.3.0+ Fix from $1,6002023-05-03 HIGH 8.1 CVE-2023-28656 NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned environment.   Note: So… Nginx Api Connectivity Manager 1.3.0 / 1.5.0+ Fix from $1,9502023-05-03