Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2024-21763
When BIG-IP AFM Device DoS or DoS profile is configured with NXDOMAIN attack vector and bad actor detection, undisclosed queries can cause the Traffi…
Big Ip Advanced Firewall Manager
17.1.1+
HIGH 7.5
CVE-2024-21771
For unspecified traffic patterns, BIG-IP AFM IPS engine may spend an excessive amount of time matching the traffic against signatures, resulting in T…
Big Ip Advanced Firewall Manager
15.1.9 / 16.1.4+
HIGH 7.5
CVE-2023-45886
The BGP daemon (bgpd) in IP Infusion ZebOS through 7.10.6 allow remote attackers to cause a denial of service by sending crafted BGP update messages …
Big Ip Next
after 17.1.1
CRITICAL 9.8
CVE-2023-46747 KEVEPSS 97%
Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the manag…
Big Ip Access Policy Manager
after 17.1.1
HIGH 8.8
CVE-2023-46748 KEV
An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which
may allow an authenticated attacker with network acce…
Big Ip Access Policy Manager
after 17.1.1
HIGH 7.8
CVE-2023-5450
An insufficient verification of data vulnerability exists in BIG-IP Edge Client Installer on macOS that may allow an attacker elevation of privileges…
Big Ip Access Policy Manager
7.2.4.5 / 15.1.10+
HIGH 7.4
CVE-2023-45226
The BIG-IP SPK TMM (Traffic Management Module) f5-debug-sidecar and f5-debug-sshd containers contains hardcoded credentials that may allow an attacke…
Big Ip Next Service Proxy For Kubernetes
Mitigation only
CRITICAL 9.9
CVE-2023-41373
A directory traversal vulnerability exists in the BIG-IP Configuration Utility that may allow an authenticated attacker to execute commands on the BI…
Big Ip Access Policy Manager
14.1.5.6 / 15.1.10.2+
HIGH 8.7
CVE-2023-43746
When running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing BI…
Big Ip Access Policy Manager
15.1.9 / 16.1.4+
HIGH 7.8
CVE-2023-43611
The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installation process. This vulnerabilit…
Big Ip Access Policy Manager
7.2.4.4 / 15.1.9+
HIGH 7.5
CVE-2023-41085
When IPSec is configured on a Virtual Server, undisclosed traffic can cause TMM to terminate.
Note: Software versions which have reached End of Tec…
Big Ip Access Policy Manager
15.1.9 / 16.1.4+
HIGH 7.2
CVE-2023-42768
When a non-admin user has been assigned an administrator role via an iControl REST PUT request and later the user's role is reverted back to a non-ad…
Big Ip Access Policy Manager
15.1.9 / 16.1.4+
MEDIUM 6.5
CVE-2023-41964
The BIG-IP and BIG-IQ systems do not encrypt some sensitive information written to Database (DB) variables.
Note: Software versions which have reac…
Big Ip Access Policy Manager
15.1.9 / 16.1.4+
MEDIUM 5.5
CVE-2023-41253
When on BIG-IP DNS or BIG-IP LTM enabled with DNS Services License, and a TSIG key is created, it is logged in plaintext in the audit log. Note: Sof…
Big Ip Domain Name System
15.1.9 / 16.1.4+
MEDIUM 5.5
CVE-2023-43485
When TACACS+ audit forwarding is configured on BIG-IP or BIG-IQ system, sharedsecret is logged in plaintext in the audit log. Note: Software version…
Big Iq Centralized Management
8.2.0.1.0.13.97-eng / 8.3.0.0.12.118-eng+
HIGH 8.1
CVE-2023-40537
An authenticated user's session cookie may remain valid for a limited time after logging out from the BIG-IP Configuration utility on a multi-blade V…
Big Ip Access Policy Manager
15.1.9 / 16.1.4+
HIGH 7.5
CVE-2023-40534
When a client-side HTTP/2 profile and the HTTP MRF Router option are enabled for a virtual server, and an iRule using the HTTP_REQUEST event or Local…
Big Ip Access Policy Manager
16.1.4.1+
HIGH 7.5
CVE-2023-40542
When TCP Verified Accept is enabled on a TCP profile that is configured on a Virtual Server, undisclosed requests can cause an increase in memory res…
Big Ip Access Policy Manager
15.1.9 / 16.1.4+
HIGH 8.2
CVE-2023-43125
BIG-IP APM clients may send IP traffic outside of the VPN tunnel. Note: Software versions which have reached End of Technical Support (EoTS) are not…
Big Ip Access Policy Manager
after 16.1.4
HIGH 7.1
CVE-2023-43124
BIG-IP APM clients may send IP traffic outside of the VPN tunnel. Note: Software versions which have reached End of Technical Support (EoTS) are not…
Big Ip Access Policy Manager
after 16.1.4
HIGH 7.8
CVE-2023-38418
The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installation process. Note: Software ve…
Access Policy Manager Clients
7.2.4.3+
MEDIUM 6.1
CVE-2023-38138
A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which allows an attacker to ru…
Big Ip Access Policy Manager
14.1.5.5 / 15.1.9.1+
MEDIUM 6.1
CVE-2023-3470
Specific F5 BIG-IP platforms with Cavium Nitrox FIPS HSM cards generate a deterministic password for the Crypto User account. The predictable nature…
Big Ip Access Policy Manager
13.1.4 / 14.1.4+
MEDIUM 5.5
CVE-2023-36858
An insufficient verification of data vulnerability exists in BIG-IP Edge Client for Windows and macOS that may allow an attacker to modify its config…
Access Policy Manager Clients
7.2.4.3+
MEDIUM 5.4
CVE-2023-38423
A cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScrip…
Big Ip Access Policy Manager
14.1.5.5 / 15.1.9.1+
HIGH 8.8
CVE-2023-28742
When DNS is provisioned, an authenticated remote command execution vulnerability exists in DNS iQuery mesh.
Note: Software versions which have r…
Big Ip Domain Name System
14.1.5.4 / 15.1.8.2+
HIGH 7.5
CVE-2023-29163
When UDP profile with idle timeout set to immediate or the value 0 is configured on a virtual server, undisclosed traffic can cause TMM to terminate.…
Big Ip Access Policy Manager
14.1.5.4 / 15.1.8.2+
HIGH 7.1
CVE-2023-28724
NGINX Management Suite default file permissions are set such that an authenticated attacker may be able to modify sensitive files on NGINX Instance M…
Nginx Api Connectivity Manager
1.3.0 / 1.5.0+
MEDIUM 5.4
CVE-2023-29240
An authenticated attacker granted a Viewer or Auditor role on a BIG-IQ can upload arbitrary files using an undisclosed iControl REST endpoint. Note:…
Big Iq Centralized Management
8.3.0+
HIGH 8.1
CVE-2023-28656
NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned environment.
Note: So…
Nginx Api Connectivity Manager
1.3.0 / 1.5.0+