cbcvebase.

F5 Big-Ip vulnerabilities

261 known vulnerabilities affecting f5/big-ip.

Total CVEs
261
CISA KEV
4
actively exploited
Public exploits
7
Exploited in wild
5
Severity breakdown
CRITICAL9HIGH159MEDIUM88LOW5

Vulnerabilities

Page 6 of 14
CVE-2024-22389P3HIGHCVSS 7.2≥ 17.1.0, < 17.1.1≥ 16.1.0, < 16.1.4+1 more2024-02-14
CVE-2024-22389 [HIGH] CWE-613 CVE-2024-22389: When BIG-IP is deployed in high availability (HA) and an iControl REST API token is updated, the cha When BIG-IP is deployed in high availability (HA) and an iControl REST API token is updated, the change does not sync to the peer device. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
CVE-2019-6623P3HIGHCVSS 7.5vBIG-IP 14.1.0-14.1.0.5v14.0.0-14.0.0.4+2 more2019-07-02
CVE-2019-6623 [HIGH] CVE-2019-6623: On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, and 12.1.0-12.1.4, undisclosed traffic On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, and 12.1.0-12.1.4, undisclosed traffic sent to BIG-IP iSession virtual server may cause the Traffic Management Microkernel (TMM) to restart, resulting in a Denial-of-Service (DoS).
nvd
CVE-2020-5852P3HIGHCVSS 7.5vHotfix-BIGIP-14.1.2.1.0.83.4-ENGvHotfix-BIGIP-12.1.4.1.0.97.6-ENG+1 more2020-01-14
CVE-2020-5852 [HIGH] CVE-2020-5852: Undisclosed traffic patterns received may cause a disruption of service to the Traffic Management Mi Undisclosed traffic patterns received may cause a disruption of service to the Traffic Management Microkernel (TMM). This vulnerability affects TMM through a virtual server configured with a FastL4 profile. Traffic processing is disrupted while TMM restarts. This issue only impacts specific engineering hotfixes. NOTE: This vulnerability does not affect any of t
nvd
CVE-2019-6684P3HIGHCVSS 7.5v15.0.0-15.0.1.1v14.0.0-14.1.2.2+3 more2019-12-23
CVE-2019-6684 [HIGH] CVE-2019-6684: On versions 15.0.0-15.0.1.1, 14.0.0-14.1.2.2, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, u On versions 15.0.0-15.0.1.1, 14.0.0-14.1.2.2, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, under certain conditions, a multi-bladed BIG-IP Virtual Clustered Multiprocessing (vCMP) may drop broadcast packets when they are rebroadcast to the vCMP guest secondary blades. An attacker can leverage the fragmented broadcast IP packets to perform any type of fr
nvd
CVE-2022-28701P3HIGHCVSS 7.5≥ 16.1.x, < 16.1.2.22022-05-05
CVE-2022-28701 [HIGH] CWE-400 CVE-2022-28701: On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, when the stream profile is configured on a virtual s On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, when the stream profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
CVE-2022-28705P3HIGHCVSS 7.5≥ 16.1.x, < 16.1.2.2≥ 15.1.x, < 15.1.5.1+2 more2022-05-05
CVE-2022-28705 [HIGH] CWE-190 CVE-2022-28705: On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions p On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, on platforms with an ePVA and the pva.fwdaccel BigDB variable enabled, undisclosed requests to a virtual server with a FastL4 profile that has ePVA acceleration enabled can cause the Traffic Managem
nvd
CVE-2022-28691P3HIGHCVSS 7.5≥ 16.1.x, < 16.1.2.2≥ 15.1.x, < 15.1.5+2 more2022-05-05
CVE-2022-28691 [HIGH] CWE-400 CVE-2022-28691: On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5, 14.1.x versions pri On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, when a Real Time Streaming Protocol (RTSP) profile is configured on a virtual server, undisclosed traffic can cause an increase in Traffic Management Microkernel (TMM) resource utilization. Note: Soft
nvd
CVE-2022-26370P3HIGHCVSS 7.5≥ 16.1.x, < 16.1.2.2≥ 15.1.x, < 15.1.5+1 more2022-05-05
CVE-2022-26370 [HIGH] CWE-908 CVE-2022-26370: On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5, and 14.1.x versions On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5, and 14.1.x versions prior to 14.1.4.6, when a Session Initiation Protocol (SIP) message routing framework (MRF) application layer gateway (ALG) profile is configured on a Message Routing virtual server, undisclosed requests can cause the Traffic Management Microkernel (TM
nvd
CVE-2022-28706P3HIGHCVSS 7.5≥ 16.1.x, < 16.1.2≥ 15.1.x, < 15.1.5.12022-05-05
CVE-2022-28706 [HIGH] CWE-754 CVE-2022-28706: On F5 BIG-IP 16.1.x versions prior to 16.1.2 and 15.1.x versions prior to 15.1.5.1, when the DNS res On F5 BIG-IP 16.1.x versions prior to 16.1.2 and 15.1.x versions prior to 15.1.5.1, when the DNS resolver configuration is used, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
CVE-2022-29473P3HIGHCVSS 7.5≥ 15.1.x, < 15.1.5.1≥ 14.1.x, < 14.1.4.6+1 more2022-05-05
CVE-2022-29473 [HIGH] CWE-754 CVE-2022-29473: On F5 BIG-IP 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versio On F5 BIG-IP 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, when an IPSec ALG profile is configured on a virtual server, undisclosed responses can cause Traffic Management Microkernel(TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluat
nvd
CVE-2022-35240P3HIGHCVSS 7.5≥ 14.1.x, < 14.1.5≥ 15.1.x, < 15.1.6.1+1 more2022-08-04
CVE-2022-35240 [HIGH] CWE-404 CVE-2022-35240: In BIG-IP Versions 16.1.x before 16.1.2.2, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when th In BIG-IP Versions 16.1.x before 16.1.2.2, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when the Message Routing (MR) Message Queuing Telemetry Transport (MQTT) profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (
nvd
CVE-2023-22839P3HIGHCVSS 7.5≥ 17.0.0, < 17.0.0.2≥ 16.1.0, < 16.1.3.3+3 more2023-02-01
CVE-2023-22839 [HIGH] CWE-476 CVE-2023-22839: On BIG-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x be On BIG-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all version of 13.1.x, when a DNS profile with the Rapid Response Mode setting enabled is configured on a virtual server with hardware SYN cookies enabled, undisclosed requests cause the Traffic Management Microkernel (TMM) to termina
nvd
CVE-2023-22340P3HIGHCVSS 7.5≥ 16.1.0, < 16.1.3.3≥ 15.1.0, < 15.1.8+2 more2023-02-01
CVE-2023-22340 [HIGH] CWE-476 CVE-2023-22340: On BIG-IP versions 16.1.x before 16.1.3.3, 15.1.x before 15.1.8, 14.1.x before 14.1.5.3, and all ver On BIG-IP versions 16.1.x before 16.1.3.3, 15.1.x before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a SIP profile is configured on a Message Routing type virtual server, undisclosed traffic can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-22281P3HIGHCVSS 7.5≥ 17.0.0, < 17.0.0.2≥ 16.1.0, < 16.1.3.3+3 more2023-02-01
CVE-2023-22281 [HIGH] CWE-908 CVE-2023-22281: On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8, 14.1.x before 14.1 On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a BIG-IP AFM NAT policy with a destination NAT rule is configured on a FastL4 virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have
nvd
CVE-2023-22842P3HIGHCVSS 7.5≥ 16.1.0, < 16.1.3.3≥ 15.1.0, < 15.1.8.1+2 more2023-02-01
CVE-2023-22842 [HIGH] CWE-121 CVE-2023-22842: On BIG-IP versions 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all v On BIG-IP versions 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a SIP profile is configured on a Message Routing type virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS)
nvd
CVE-2023-22341P3HIGHCVSS 7.5≥ 14.1.0, < 14.1.5.3≥ 13.1.0, < *2023-02-01
CVE-2023-22341 [HIGH] CWE-476 CVE-2023-22341: On version 14.1.x before 14.1.5.3, and all versions of 13.1.x, when the BIG-IP APM system is configu On version 14.1.x before 14.1.5.3, and all versions of 13.1.x, when the BIG-IP APM system is configured with all the following elements, undisclosed requests may cause the Traffic Management Microkernel (TMM) to terminate: * An OAuth Server that references an OAuth Provider * An OAuth profile with the Authorization Endpoint set to '/' * An access pro
nvd
CVE-2024-33608P3HIGHCVSS 7.5≥ 17.1.0, < 17.1.12024-05-08
CVE-2024-33608 [HIGH] CWE-824 CVE-2024-33608: When IPsec is configured on a virtual server, undisclosed traffic can cause the Traffic Management M When IPsec is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-40542P3HIGHCVSS 7.5≥ 16.1.0, < 16.1.4≥ 15.1.0, < 15.1.9+2 more2023-10-10
CVE-2023-40542 [HIGH] CWE-770 CVE-2023-40542: When TCP Verified Accept is enabled on a TCP profile that is configured on a Virtual Server, undiscl When TCP Verified Accept is enabled on a TCP profile that is configured on a Virtual Server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
CVE-2023-40534P3HIGHCVSS 7.5≥ 17.1.0, < 17.1.0.3.0.23.4-ENG≥ 16.1.0, < 16.1.4.1.0.13.5-ENG2023-10-10
CVE-2023-40534 [HIGH] CWE-401 CVE-2023-40534: When a client-side HTTP/2 profile and the HTTP MRF Router option are enabled for a virtual server, a When a client-side HTTP/2 profile and the HTTP MRF Router option are enabled for a virtual server, and an iRule using the HTTP_REQUEST event or Local Traffic Policy are associated with the virtual server, undisclosed requests can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2024-24775P3HIGHCVSS 7.5≥ 17.1.0, < 17.1.1≥ 16.1.0, < 16.1.4+1 more2024-02-14
CVE-2024-24775 [HIGH] CWE-476 CVE-2024-24775: When a virtual server is enabled with VLAN group and SNAT listener is configured, undisclosed traffi When a virtual server is enabled with VLAN group and SNAT listener is configured, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
F5 Big-Ip vulnerabilities | cvebase