F5 Big-Ip vulnerabilities
216 known vulnerabilities affecting f5/big-ip.
Total CVEs
216
CISA KEV
4
actively exploited
Public exploits
7
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH139MEDIUM64LOW5
Vulnerabilities
Page 11 of 11
CVE-2019-6629HIGHCVSS 7.5vBIG-IP 14.1.0-14.1.0.52019-07-03
CVE-2019-6629 [HIGH] CVE-2019-6629: On BIG-IP 14.1.0-14.1.0.5, undisclosed SSL traffic to a virtual server configured with a Client SSL
On BIG-IP 14.1.0-14.1.0.5, undisclosed SSL traffic to a virtual server configured with a Client SSL profile may cause TMM to fail and restart. The Client SSL profile must have session tickets enabled and use DHE cipher suites to be affected. This only impacts the data plane, there is no impact to the control plane.
cvelistv5nvd
CVE-2019-6634MEDIUMCVSS 6.5vBIG-IP 14.1.0-14.1.0.5v14.0.0-14.0.0.4+2 more2019-07-03
CVE-2019-6634 [MEDIUM] CVE-2019-6634: On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, and 12.1.0-12.1.4, a high volume of mal
On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, and 12.1.0-12.1.4, a high volume of malformed analytics report requests leads to instability in restjavad process. This causes issues with both iControl REST and some portions of TMUI. The attack requires an authenticated user with any role.
cvelistv5nvd
CVE-2019-6633MEDIUMCVSS 4.4vBIG-IP 14.1.0-14.1.0.5v14.0.0-14.0.0.4+3 more2019-07-03
CVE-2019-6633 [MEDIUM] CVE-2019-6633: On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4.1, and 11.5.1-11.6.4, whe
On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4.1, and 11.5.1-11.6.4, when the BIG-IP system is licensed with Appliance mode, user accounts with Administrator and Resource Administrator roles can bypass Appliance mode restrictions.
cvelistv5nvd
CVE-2019-6638MEDIUMCVSS 6.5vBIG-IP 14.1.0-14.1.0.5v14.0.0-14.0.0.42019-07-03
CVE-2019-6638 [MEDIUM] CWE-835 CVE-2019-6638: On BIG-IP 14.1.0-14.1.0.5 and 14.0.0-14.0.0.4, Malformed http requests made to an undisclosed iContr
On BIG-IP 14.1.0-14.1.0.5 and 14.0.0-14.0.0.4, Malformed http requests made to an undisclosed iControl REST endpoint can lead to infinite loop of the restjavad process.
cvelistv5nvd
CVE-2019-6641MEDIUMCVSS 6.5vBIG-IP 12.1.0-12.1.4.12019-07-03
CVE-2019-6641 [MEDIUM] CVE-2019-6641: On BIG-IP 12.1.0-12.1.4.1, undisclosed requests can cause iControl REST processes to crash. The atta
On BIG-IP 12.1.0-12.1.4.1, undisclosed requests can cause iControl REST processes to crash. The attack can only come from an authenticated user; all roles are capable of performing the attack. Unauthenticated users cannot perform this attack.
cvelistv5nvd
CVE-2019-6632MEDIUMCVSS 5.5vBIG-IP 14.1.0-14.1.0.5v14.0.0-14.0.0.4+2 more2019-07-03
CVE-2019-6632 [MEDIUM] CWE-330 CVE-2019-6632: On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, and 12.1.0-12.1.4, under certain circum
On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, and 12.1.0-12.1.4, under certain circumstances, attackers can decrypt configuration items that are encrypted because the vCMP configuration unit key is generated with insufficient randomness. The attack prerequisite is direct access to encrypted configuration and/or UCS files.
cvelistv5nvd
CVE-2019-6637MEDIUMCVSS 6.5vBIG-IP (ASM) 14.1.0-14.1.0.5v14.0.0-14.0.0.4+2 more2019-07-03
CVE-2019-6637 [MEDIUM] CVE-2019-6637: On BIG-IP (ASM) 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, and 12.1.0-12.1.4, Application lo
On BIG-IP (ASM) 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, and 12.1.0-12.1.4, Application logic abuse of ASM REST endpoints can lead to instability of BIG-IP system. Exploitation of this issue causes excessive memory consumption which results in the Linux kernel triggering OOM killer on arbitrary processes. The attack requires an authenticated user wi
cvelistv5nvd
CVE-2019-6625MEDIUMCVSS 6.1vBIG-IP 14.1.0-14.1.0.5v14.0.0-14.0.0.4+3 more2019-07-03
CVE-2019-6625 [MEDIUM] CWE-79 CVE-2019-6625: On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, and 11.5.1-11.6.4, a ref
On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, and 11.5.1-11.6.4, a reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Traffic Management User Interface (TMUI) also known as the BIG-IP Configuration utility.
cvelistv5nvd
CVE-2019-6640MEDIUMCVSS 5.3vBIG-IP 14.1.0-14.1.0.5v14.0.0-14.0.0.4+4 more2019-07-03
CVE-2019-6640 [MEDIUM] CWE-319 CVE-2019-6640: On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.
On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.1-11.5.8, SNMP exposes sensitive configuration objects over insecure transmission channels. This issue is exposed when a passphrase is inserted into various profile types and accessed using SNMPv2.
cvelistv5nvd
CVE-2019-6635MEDIUMCVSS 4.4vBIG-IP 14.1.0-14.1.0.5v14.0.0-14.0.0.4+4 more2019-07-03
CVE-2019-6635 [MEDIUM] CVE-2019-6635: On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.
On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.1-11.5.8, when the BIG-IP system is licensed for Appliance mode, a user with either the Administrator or the Resource Administrator role can bypass Appliance mode restrictions.
cvelistv5nvd
CVE-2019-6624HIGHCVSS 7.5vBIG-IP 14.1.0-14.1.0.5v14.0.0-14.0.0.4+2 more2019-07-02
CVE-2019-6624 [HIGH] CVE-2019-6624: On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, and 12.1.0-12.1.4, an undisclosed traff
On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, and 12.1.0-12.1.4, an undisclosed traffic pattern sent to a BIG-IP UDP virtual server may lead to a denial-of-service (DoS).
cvelistv5nvd
CVE-2019-6623HIGHCVSS 7.5vBIG-IP 14.1.0-14.1.0.5v14.0.0-14.0.0.4+2 more2019-07-02
CVE-2019-6623 [HIGH] CVE-2019-6623: On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, and 12.1.0-12.1.4, undisclosed traffic
On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, and 12.1.0-12.1.4, undisclosed traffic sent to BIG-IP iSession virtual server may cause the Traffic Management Microkernel (TMM) to restart, resulting in a Denial-of-Service (DoS).
cvelistv5nvd
CVE-2019-6622HIGHCVSS 7.2vBIG-IP 14.1.0-14.1.0.5v14.0.0-14.0.0.5+3 more2019-07-02
CVE-2019-6622 [HIGH] CWE-77 CVE-2019-6622: On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.5, 13.0.0-13.1.1.4, 12.1.0-12.1.4.1, and 11.5.1-11.6.4, an
On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.5, 13.0.0-13.1.1.4, 12.1.0-12.1.4.1, and 11.5.1-11.6.4, an undisclosed iControl REST worker is vulnerable to command injection by an administrator or resource administrator user. This attack is only exploitable on multi-bladed systems.
cvelistv5nvd
CVE-2014-9342MEDIUMCVSS 4.3v11.3.02014-12-08
CVE-2014-9342 [MEDIUM] CWE-79 CVE-2014-9342: Cross-site scripting (XSS) vulnerability in the tree view (pl_tree.php) feature in Application Secur
Cross-site scripting (XSS) vulnerability in the tree view (pl_tree.php) feature in Application Security Manager (ASM) in F5 BIG-IP 11.3.0 allows remote attackers to inject arbitrary web script or HTML by accessing a crafted URL during automatic policy generation.
nvd
CVE-2008-7032MEDIUMCVSS 6.8PoCv9.4.32009-08-24
CVE-2008-7032 [MEDIUM] CWE-352 CVE-2008-7032: Web Management Console Cross-site request forgery (CSRF) vulnerability in the web management console
Web Management Console Cross-site request forgery (CSRF) vulnerability in the web management console in F5 BIG-IP 9.4.3 allows remote attackers to hijack the authentication of administrators for requests that create new administrators and execute shell commands, as demonstrated using tmui/Control/form.
nvd
CVE-2007-6258HIGHCVSS 7.5PoCv9.2.3.302008-02-19
CVE-2007-6258 [HIGH] CWE-119 CVE-2007-6258: Multiple stack-based buffer overflows in the legacy mod_jk2 2.0.3-DEV and earlier Apache module allo
Multiple stack-based buffer overflows in the legacy mod_jk2 2.0.3-DEV and earlier Apache module allow remote attackers to execute arbitrary code via a long (1) Host header, or (2) Hostname within a Host header.
nvd
← Previous11 / 11