cbcvebase.

F5 Big-Ip vulnerabilities

261 known vulnerabilities affecting f5/big-ip.

Total CVEs
261
CISA KEV
4
actively exploited
Public exploits
7
Exploited in wild
5
Severity breakdown
CRITICAL9HIGH159MEDIUM88LOW5

Vulnerabilities

Page 4 of 14
CVE-2022-34844P3HIGHCVSS 7.5≥ 15.1.x, < 15.1.6.1≥ 16.1.x, < 16.1.3.12022-08-04
CVE-2022-34844 [HIGH] CWE-20 CVE-2022-34844: In BIG-IP Versions 16.1.x before 16.1.3.1 and 15.1.x before 15.1.6.1, and all versions of BIG-IQ 8.x In BIG-IP Versions 16.1.x before 16.1.3.1 and 15.1.x before 15.1.6.1, and all versions of BIG-IQ 8.x, when the Data Plane Development Kit (DPDK)/Elastic Network Adapter (ENA) driver is used with BIG-IP or BIG-IQ on Amazon Web Services (AWS) systems, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Successful exploita
nvd
CVE-2022-41833P3HIGHCVSS 7.5≥ 13.1.0, < 13.1.x*2022-10-19
CVE-2022-41833 [HIGH] CWE-400 CVE-2022-41833: In all BIG-IP 13.1.x versions, when an iRule containing the HTTP::collect command is configured on a In all BIG-IP 13.1.x versions, when an iRule containing the HTTP::collect command is configured on a virtual server, undisclosed requests can cause Traffic Management Microkernel (TMM) to terminate.
nvd
CVE-2025-61974P3HIGHCVSS 7.5≥ 17.5.0, < 17.5.1.3≥ 17.1.0, < 17.1.3+2 more2025-10-15
CVE-2025-61974 [HIGH] CWE-401 CVE-2025-61974: When a client SSL profile is configured on a virtual server, undisclosed requests can cause an incre When a client SSL profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2025-22891P3HIGHCVSS 7.5≥ 17.1.0, < 17.1.2≥ 16.1.0, < 16.1.5+1 more2025-02-05
CVE-2025-22891 [HIGH] CWE-772 CVE-2025-22891: When BIG-IP PEM Control Plane listener Virtual Server is configured with Diameter Endpoint profile, When BIG-IP PEM Control Plane listener Virtual Server is configured with Diameter Endpoint profile, undisclosed traffic can cause the Virtual Server to stop processing new client connections and an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2025-23412P3HIGHCVSS 7.5≥ 17.1.0, < 17.1.2≥ 16.1.3, < 16.1.52025-02-05
CVE-2025-23412 [HIGH] CWE-120 CVE-2025-23412: When BIG-IP APM Access Profile is configured on a virtual server, undisclosed request can cause TMM When BIG-IP APM Access Profile is configured on a virtual server, undisclosed request can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2025-55669P3HIGHCVSS 7.5≥ 17.1.0, < 17.1.2.2≥ 16.1.0, < 16.1.62025-10-15
CVE-2025-55669 [HIGH] CWE-672 CVE-2025-55669: When the BIG-IP Advanced WAF and ASM security policy and a server-side HTTP/2 profile are configured When the BIG-IP Advanced WAF and ASM security policy and a server-side HTTP/2 profile are configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2025-46405P3HIGHCVSS 7.5≥ 17.1.0, < 17.1.2.2≥ 16.1.0, < 16.1.6+1 more2025-08-13
CVE-2025-46405 [HIGH] CWE-121 CVE-2025-46405: When Network Access is configured on a BIG-IP APM virtual server, undisclosed traffic can cause the When Network Access is configured on a BIG-IP APM virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2025-52585P3HIGHCVSS 7.5≥ 17.1.0, < 17.1.2.2≥ 16.1.0, < 16.1.6+1 more2025-08-13
CVE-2025-52585 [HIGH] CWE-476 CVE-2025-52585: When a BIG-IP LTM Client SSL profile is configured on a virtual server with SSL Forward Proxy enable When a BIG-IP LTM Client SSL profile is configured on a virtual server with SSL Forward Proxy enabled and Anonymous Diffie-Hellman (ADH) ciphers enabled, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2025-61935P3HIGHCVSS 7.5≥ 17.5.0, < 17.5.1≥ 17.1.0, < 17.1.3+1 more2025-10-15
CVE-2025-61935 [HIGH] CWE-252 CVE-2025-61935: When a BIG IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed req When a BIG IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-40629P3HIGHCVSS 7.5≥ 17.5.0, < 17.5.1.4≥ 17.1.0, < 17.1.3.1+1 more2026-05-13
CVE-2026-40629 [HIGH] CWE-770 CVE-2026-40629: When SSL profiles are configured on a virtual server, undisclosed traffic can cause the virtual serv When SSL profiles are configured on a virtual server, undisclosed traffic can cause the virtual server to stop processing new client connections. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-40618P3HIGHCVSS 7.5≥ 21.0.0, < 21.0.0.1≥ 17.5.0, < 17.1.5.4+2 more2026-05-13
CVE-2026-40618 [HIGH] CWE-131 CVE-2026-40618: When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel Q When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel QuickAssist Technology (QAT) or on BIG-IP hardware platforms with the database variable crypto.hwacceleration set to disabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reache
nvd
CVE-2025-61938P3HIGHCVSS 7.5≥ 17.5.0, < 17.5.1≥ 17.1.0, < 17.1.32025-10-15
CVE-2025-61938 [HIGH] CWE-1284 CVE-2025-61938: When a BIG-IP Advanced WAF or ASM security policy is configured with a URL greater than 1024 charact When a BIG-IP Advanced WAF or ASM security policy is configured with a URL greater than 1024 characters in length for the Data Guard Protection Enforcement setting, either manually or through the automatic Policy Builder, the bd process can terminate repeatedly. Note: Software versions which have reached End of Technical Support (EoTS) are not evalua
nvd
CVE-2025-53474P3HIGHCVSS 7.5≥ 17.5.0, < 17.5.1.3≥ 17.1.0, < 17.1.3+2 more2025-10-15
CVE-2025-53474 [HIGH] CWE-120 CVE-2025-53474: When an iRule using an ILX::call command is configured on a virtual server, undisclosed traffic can When an iRule using an ILX::call command is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2025-58096P3HIGHCVSS 7.5≥ 17.5.0, < 17.5.1.3≥ 17.1.0, < 17.1.3+2 more2025-10-15
CVE-2025-58096 [HIGH] CWE-787 CVE-2025-58096: When the database variable tm.tcpudptxchecksum is configured as non-default value Software-only on a When the database variable tm.tcpudptxchecksum is configured as non-default value Software-only on a BIG-IP system, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-40423P3HIGHCVSS 7.5≥ 21.0.0, < 21.0.0.2≥ 17.5.0, < 17.5.1.6+2 more2026-05-13
CVE-2026-40423 [HIGH] CWE-770 CVE-2026-40423: When a SIP profile is configured on a virtual server, undisclosed traffic can cause the Traffic Mana When a SIP profile is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-42920P3HIGHCVSS 7.5≥ 21.0.0, < 21.0.0.1≥ 17.5.0, < 17.5.1.4+2 more2026-05-13
CVE-2026-42920 [HIGH] CWE-835 CVE-2026-42920: When a Client SSL profile is configured with Allow Dynamic Record Sizing on a UDP virtual server, un When a Client SSL profile is configured with Allow Dynamic Record Sizing on a UDP virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2025-61951P3HIGHCVSS 7.5≥ 17.5.0, < 17.5.1≥ 17.1.0, < 17.1.3+1 more2025-10-15
CVE-2025-61951 [HIGH] CWE-125 CVE-2025-61951: Undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. This issue may Undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. This issue may occur when a Datagram Transport Layer Security (DTLS) 1.2 virtual server is enabled with a Server SSL profile that is configured with a certificate, key, and the SSL Sign Hash set to ANY, and the backend server is enabled with DTLS 1.2 and client authent
nvd
CVE-2022-28716P3HIGHCVSS 8.8v12.1.xv11.6.x+4 more2022-05-05
CVE-2022-28716 [HIGH] CWE-79 CVE-2022-28716: On 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14 On 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x 11.6.x, a DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP AFM, CGNAT, and PEM Configuration utility that allows an attacker to execute Java
nvd
CVE-2023-40537P3HIGHCVSS 8.1≥ 16.1.0, < 16.1.4≥ 15.1.0, < 15.1.9+2 more2023-10-10
CVE-2023-40537 [HIGH] CWE-613 CVE-2023-40537: An authenticated user's session cookie may remain valid for a limited time after logging out from t An authenticated user's session cookie may remain valid for a limited time after logging out from the BIG-IP Configuration utility on a multi-blade VIPRION platform. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2022-27189P3HIGHCVSS 7.5v12.1.xv11.6.x+4 more2022-05-05
CVE-2022-27189 [HIGH] CWE-681 CVE-2022-27189: On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions p On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, when an Internet Content Adaptation Protocol (ICAP) profile is configured on a virtual server, undisclosed traffic can cause an increase in Traffic Management Micr
nvd
F5 Big-Ip vulnerabilities | cvebase