F5 Big-Ip vulnerabilities
259 known vulnerabilities affecting f5/big-ip.
Total CVEs
259
CISA KEV
4
actively exploited
Public exploits
7
Exploited in wild
5
Severity breakdown
CRITICAL9HIGH158MEDIUM88LOW4
Vulnerabilities
Page 1 of 13
CVE-2022-1388P1CRITICALCVSS 9.8KEVPoCRansomware≥ 16.1.x, < 16.1.2.2≥ 15.1.x, < 15.1.5.1+4 more2022-05-05
CVE-2022-1388 [CRITICAL] CWE-306 CVE-2022-1388: On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions p
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
CVE-2023-46747P1CRITICALCVSS 9.8KEVPoCRansomware≥ 17.1.0, < *≥ 16.1.0, < *+3 more2023-10-26
CVE-2023-46747 [CRITICAL] CWE-288 CVE-2023-46747: Undisclosed requests may bypass configuration utility authentication, allowing an attacker with netw
Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
CVE-2025-53521P1CRITICALCVSS 9.8KEV≥ 17.5.0, < 17.5.1.3≥ 17.1.0, < 17.1.3+2 more2025-10-15
CVE-2025-53521 [CRITICAL] CWE-121 CVE-2025-53521: When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can le
When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-46748P1HIGHCVSS 8.8KEV≥ 17.1.0, < *≥ 16.1.0, < *+3 more2023-10-26
CVE-2023-46748 [HIGH] CWE-89 CVE-2023-46748: An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may
An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which
may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresses to execute arbitrary system commands.
Note: Software versions which have reached End of Technical Support (EoTS) are
nvd
CVE-2022-41800P1HIGHCVSS 8.7ExploitedPoCv17.0.xv16.1.x+3 more2022-12-07
CVE-2022-41800 [HIGH] CWE-77 CVE-2022-41800: In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Admin
In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary.
Note: Software versions which have reached End of Technical Support
nvd
CVE-2022-41622P2HIGHCVSS 8.8PoCv17.xv16.1.x+3 more2022-12-07
CVE-2022-41622 [HIGH] CWE-352 CVE-2022-41622: In all versions, BIG-IP and BIG-IQ are vulnerable to cross-site request forgery (CSRF) attacks thr
In all versions,
BIG-IP and BIG-IQ are vulnerable to cross-site request forgery (CSRF) attacks through iControl SOAP.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2007-6258P3HIGHCVSS 7.5PoCv9.2.3.302008-02-19
CVE-2007-6258 [HIGH] CWE-119 CVE-2007-6258: Multiple stack-based buffer overflows in the legacy mod_jk2 2.0.3-DEV and earlier Apache module allo
Multiple stack-based buffer overflows in the legacy mod_jk2 2.0.3-DEV and earlier Apache module allow remote attackers to execute arbitrary code via a long (1) Host header, or (2) Hostname within a Host header.
nvd
CVE-2023-22374P2HIGHCVSS 8.5≥ 17.0.0, < 17.1.0≥ 16.1.2.2, < 16.1.3.4+3 more2023-02-01
CVE-2023-22374 [HIGH] CWE-134 CVE-2023-22374: A format string vulnerability exists in iControl SOAP that allows an authenticated attacker to cras
A format string vulnerability exists in iControl SOAP that allows an authenticated attacker to crash the iControl SOAP CGI process or, potentially execute arbitrary code. In appliance mode BIG-IP, a successful exploit of this vulnerability can allow the attacker to cross a security boundary.
Note: Software versions which have reached End of Technical S
nvd
CVE-2025-31644P2HIGHCVSS 8.7≥ 17.1.0, < 17.1.2.2≥ 16.1.0, < 16.1.6+1 more2025-05-07
CVE-2025-31644 [HIGH] CWE-77 CVE-2025-31644: When running in Appliance mode, a command injection vulnerability exists in an undisclosed iControl
When running in Appliance mode, a command injection vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command which may allow an authenticated attacker with administrator role privileges to execute arbitrary system commands. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions
nvd
CVE-2023-23552P3HIGHCVSS 7.5PoC≥ 17.0.0, < 17.0.0.2≥ 16.1.0, < 16.1.3.3+3 more2023-02-01
CVE-2023-23552 [HIGH] CWE-400 CVE-2023-23552: On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.0 before 15.1.8, 14.1.x before 14.1
On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.0 before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a BIG-IP Advanced WAF or BIG-IP ASM security policy is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Te
nvd
CVE-2023-41373P2CRITICALCVSS 9.9≥ 17.1.0, < 17.1.0.3≥ 16.1.0, < 16.1.4.1+3 more2023-10-10
CVE-2023-41373 [CRITICAL] CWE-22 CVE-2023-41373: A directory traversal vulnerability exists in the BIG-IP Configuration Utility that may allow an au
A directory traversal vulnerability exists in the BIG-IP Configuration Utility that may allow an authenticated attacker to execute commands on the BIG-IP system. For BIG-IP system running in Appliance mode, a successful exploit can allow the attacker to cross a security boundary.
Note: Software versions which have reached End of Technical Support (
nvd
CVE-2025-20029P2HIGHCVSS 8.8≥ 17.1.0, < 17.1.2.1≥ 16.1.0, < 16.1.5.2+1 more2025-02-05
CVE-2025-20029 [HIGH] CWE-78 CVE-2025-20029: Command injection vulnerability exists in iControl REST and BIG-IP TMOS Shell (tmsh) save command, w
Command injection vulnerability exists in iControl REST and BIG-IP TMOS Shell (tmsh) save command, which may allow an authenticated attacker to execute arbitrary system commands.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-41957P2HIGHCVSS 8.8≥ 17.5.0, < 17.5.1.4≥ 17.1.0, < 17.1.3.1+1 more2026-05-13
CVE-2026-41957 [HIGH] CWE-502 CVE-2026-41957: An authenticated remote code execution vulnerability through undisclosed vectors exists in the BIG-I
An authenticated remote code execution vulnerability through undisclosed vectors exists in the BIG-IP and BIG-IQ Configuration utility.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-41225P3CRITICALCVSS 9.1≥ 21.0.0, < 21.0.0.2≥ 17.5.0, < 17.5.1.6+2 more2026-05-13
CVE-2026-41225 [CRITICAL] CWE-648 CVE-2026-41225: A vulnerability exists in iControl REST where a highly privileged, authenticated attacker with at le
A vulnerability exists in iControl REST where a highly privileged, authenticated attacker with at least the Manager role can create configuration objects that allow running arbitrary commands.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2025-59481P3HIGHCVSS 8.7≥ 17.5.0, < 17.5.1.3≥ 17.1.0, < 17.1.3+2 more2025-10-15
CVE-2025-59481 [HIGH] CWE-250 CVE-2025-59481: A vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may
A vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with at least resource administrator role to execute arbitrary system commands with higher privileges. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached
nvd
CVE-2024-45844P3HIGHCVSS 7.2≥ 17.1.0, < 17.1.1.4≥ 16.1.0, < 16.1.5+1 more2024-10-16
CVE-2024-45844 [HIGH] CWE-306 CVE-2024-45844: BIG-IP monitor functionality may allow an attacker to bypass access control restrictions, regardless
BIG-IP monitor functionality may allow an attacker to bypass access control restrictions, regardless of the port lockdown settings. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2025-61958P3HIGHCVSS 8.7≥ 17.5.0, < 17.5.1.1≥ 17.1.0, < 17.1.3+2 more2025-10-15
CVE-2025-61958 [HIGH] CWE-250 CVE-2025-61958: A vulnerability exists in the iHealth command that may allow an authenticated attacker with at least
A vulnerability exists in the iHealth command that may allow an authenticated attacker with at least a resource administrator role to bypass tmsh restrictions and gain access to a bash shell. For BIG-IP systems running in Appliance mode, a successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reache
nvd
CVE-2008-7032P4MEDIUMCVSS 6.8PoCv9.4.32009-08-24
CVE-2008-7032 [MEDIUM] CWE-352 CVE-2008-7032: Web Management Console Cross-site request forgery (CSRF) vulnerability in the web management console
Web Management Console Cross-site request forgery (CSRF) vulnerability in the web management console in F5 BIG-IP 9.4.3 allows remote attackers to hijack the authentication of administrators for requests that create new administrators and execute shell commands, as demonstrated using tmui/Control/form.
nvd
CVE-2023-28742P3HIGHCVSS 8.8≥ 17.1.0, < 17.1.0.1≥ 17.0.0, < *+4 more2023-05-03
CVE-2023-28742 [HIGH] CWE-78 CVE-2023-28742: When DNS is provisioned, an authenticated remote command execution vulnerability exists in DNS iQue
When DNS is provisioned, an authenticated remote command execution vulnerability exists in DNS iQuery mesh.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-34176P3HIGHCVSS 8.7≥ 21.0.0, < 21.0.0.2≥ 17.5.0, < 17.5.1.6+2 more2026-05-13
CVE-2026-34176 [HIGH] CWE-78 CVE-2026-34176: When running in Appliance mode, an authenticated remote command injection vulnerability exists in an
When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
1 / 13Next →