F5 Big-Ip vulnerabilities

216 known vulnerabilities affecting f5/big-ip.

Total CVEs
216
CISA KEV
4
actively exploited
Public exploits
5
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH139MEDIUM64LOW5

Vulnerabilities

Page 6 of 11
CVE-2023-45219MEDIUMCVSS 4.4≥ 16.1.0, < 16.1.4≥ 15.1.0, < 15.1.9+2 more2023-10-10
CVE-2023-45219 [MEDIUM] CWE-200 CVE-2023-45219: Exposure of Sensitive Information vulnerability exist in an undisclosed BIG-IP TMOS shell (tmsh) co Exposure of Sensitive Information vulnerability exist in an undisclosed BIG-IP TMOS shell (tmsh) command which may allow an authenticated attacker with resource administrator role privileges to view sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
cvelistv5nvd
CVE-2023-41964MEDIUMCVSS 6.5≥ 16.1.0, < 16.1.4≥ 15.1.0, < 15.1.9+2 more2023-10-10
CVE-2023-41964 [MEDIUM] CWE-312 CVE-2023-41964: The BIG-IP and BIG-IQ systems do not encrypt some sensitive information written to Database (DB) va The BIG-IP and BIG-IQ systems do not encrypt some sensitive information written to Database (DB) variables. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
cvelistv5nvd
CVE-2023-43485MEDIUMCVSS 5.5≥ 16.1.0, < 16.1.4≥ 15.1.0, < 15.1.9+2 more2023-10-10
CVE-2023-43485 [MEDIUM] CWE-532 CVE-2023-43485: When TACACS+ audit forwarding is configured on BIG-IP or BIG-IQ system, sharedsecret is logged in p When TACACS+ audit forwarding is configured on BIG-IP or BIG-IQ system, sharedsecret is logged in plaintext in the audit log. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
cvelistv5nvd
CVE-2023-41253MEDIUMCVSS 5.5≥ 16.1.0, < 16.1.4≥ 15.1.0, < 15.1.9+2 more2023-10-10
CVE-2023-41253 [MEDIUM] CWE-532 CVE-2023-41253: When on BIG-IP DNS or BIG-IP LTM enabled with DNS Services License, and a TSIG key is created, it i When on BIG-IP DNS or BIG-IP LTM enabled with DNS Services License, and a TSIG key is created, it is logged in plaintext in the audit log. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
cvelistv5nvd
CVE-2023-39447MEDIUMCVSS 4.4≥ 16.1.0, < 16.1.4≥ 15.1.0, < 15.1.8+1 more2023-10-10
CVE-2023-39447 [MEDIUM] CWE-532 CVE-2023-39447: When BIG-IP APM Guided Configurations are configured, undisclosed sensitive information may be logg When BIG-IP APM Guided Configurations are configured, undisclosed sensitive information may be logged in restnoded log. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
cvelistv5nvd
CVE-2023-3470MEDIUMCVSS 6.1≥ 15.1.0, < 15.1.1≥ 14.1.0, < 14.1.4+1 more2023-08-02
CVE-2023-3470 [MEDIUM] CWE-1391 CVE-2023-3470: Specific F5 BIG-IP platforms with Cavium Nitrox FIPS HSM cards generate a deterministic password fo Specific F5 BIG-IP platforms with Cavium Nitrox FIPS HSM cards generate a deterministic password for the Crypto User account. The predictable nature of the password allows an authenticated user with TMSH access to the BIG-IP system, or anyone with physical access to the FIPS HSM, the information required to generate the correct password. On vCMP syst
cvelistv5nvd
CVE-2023-38419MEDIUMCVSS 4.3≥ 17.1.0, < 17.1.0.2≥ 16.1.0, < 16.1.3.5+3 more2023-08-02
CVE-2023-38419 [MEDIUM] CWE-755 CVE-2023-38419: An authenticated attacker with guest privileges or higher can cause the iControl SOAP process to ter An authenticated attacker with guest privileges or higher can cause the iControl SOAP process to terminate by sending undisclosed requests. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
cvelistv5nvd
CVE-2023-38138MEDIUMCVSS 6.1≥ 17.1.0, < 17.1.0.2≥ 16.1.0, < 16.1.3.5+3 more2023-08-02
CVE-2023-38138 [MEDIUM] CWE-79 CVE-2023-38138: A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Co A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
cvelistv5nvd
CVE-2023-38423MEDIUMCVSS 5.4≥ 17.1.0, < 17.1.0.2≥ 16.1.0, < 16.1.3.5+3 more2023-08-02
CVE-2023-38423 [MEDIUM] CWE-79 CVE-2023-38423: A cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuratio A cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
cvelistv5nvd
CVE-2023-29163HIGHCVSS 7.5≥ 17.0.0, < *≥ 16.1.2.2, < 16.1.3.4+2 more2023-05-03
CVE-2023-29163 [HIGH] CWE-401 CVE-2023-29163: When UDP profile with idle timeout set to immediate or the value 0 is configured on a virtual serve When UDP profile with idle timeout set to immediate or the value 0 is configured on a virtual server, undisclosed traffic can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
cvelistv5nvd
CVE-2023-28742HIGHCVSS 8.8≥ 17.1.0, < 17.1.0.1≥ 17.0.0, < *+4 more2023-05-03
CVE-2023-28742 [HIGH] CWE-78 CVE-2023-28742: When DNS is provisioned, an authenticated remote command execution vulnerability exists in DNS iQue When DNS is provisioned, an authenticated remote command execution vulnerability exists in DNS iQuery mesh. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
cvelistv5nvd
CVE-2023-24594MEDIUMCVSS 5.3≥ 16.1.2, < 16.1.2.1≥ 15.1.4.1, < 15.1.5+1 more2023-05-03
CVE-2023-24594 [MEDIUM] CWE-400 CVE-2023-24594: When an SSL profile is configured on a Virtual Server, undisclosed traffic can cause an increase in When an SSL profile is configured on a Virtual Server, undisclosed traffic can cause an increase in CPU or SSL accelerator resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
cvelistv5nvd
CVE-2023-28406MEDIUMCVSS 4.3≥ 17.0.0, < *≥ 16.1.0, < 16.1.3.4+3 more2023-05-03
CVE-2023-28406 [MEDIUM] CWE-22 CVE-2023-28406: A directory traversal vulnerability exists in an undisclosed page of the BIG-IP Configuration utilit A directory traversal vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which may allow an authenticated attacker to read files with .xml extension. Access to restricted information is limited and the attacker does not control what information is obtained. Note: Software versions which have reached End of Technical Sup
cvelistv5nvd
CVE-2023-27378MEDIUMCVSS 6.1≥ 17.1.0, < 17.1.0.1≥ 17.0.0, < *+4 more2023-05-03
CVE-2023-27378 [MEDIUM] CWE-79 CVE-2023-27378: Multiple reflected cross-site scripting (XSS) vulnerabilities exist in undisclosed pages of the BIG Multiple reflected cross-site scripting (XSS) vulnerabilities exist in undisclosed pages of the BIG-IP Configuration utility which allow an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
cvelistv5nvd
CVE-2023-22422HIGHCVSS 7.5≥ 17.0.0, < 17.0.0.2≥ 16.1.0, < 16.1.3.32023-02-01
CVE-2023-22422 [HIGH] CWE-120 CVE-2023-22422: On BIG-IP versions 17.0.x before 17.0.0.2 and 16.1.x before 16.1.3.3, when a HTTP profile with the n On BIG-IP versions 17.0.x before 17.0.0.2 and 16.1.x before 16.1.3.3, when a HTTP profile with the non-default Enforcement options of Enforce HTTP Compliance and Unknown Methods: Reject are configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached En
cvelistv5nvd
CVE-2023-22341HIGHCVSS 7.5≥ 14.1.0, < 14.1.5.3≥ 13.1.0, < *2023-02-01
CVE-2023-22341 [HIGH] CWE-476 CVE-2023-22341: On version 14.1.x before 14.1.5.3, and all versions of 13.1.x, when the BIG-IP APM system is configu On version 14.1.x before 14.1.5.3, and all versions of 13.1.x, when the BIG-IP APM system is configured with all the following elements, undisclosed requests may cause the Traffic Management Microkernel (TMM) to terminate: * An OAuth Server that references an OAuth Provider * An OAuth profile with the Authorization Endpoint set to '/' * An access pro
cvelistv5nvd
CVE-2023-22323HIGHCVSS 7.5≥ 17.0.0, < 17.0.0.2≥ 16.1.0, < 16.1.3.3+3 more2023-02-01
CVE-2023-22323 [HIGH] CWE-770 CVE-2023-22323: In BIP-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x be In BIP-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when OCSP authentication profile is configured on a virtual server, undisclosed requests can cause an increase in CPU resource utilization. Note: Software versions which have reached End of Technical Support (E
cvelistv5nvd
CVE-2023-22374HIGHCVSS 8.5≥ 17.0.0, < 17.1.0≥ 16.1.2.2, < 16.1.3.4+3 more2023-02-01
CVE-2023-22374 [HIGH] CWE-134 CVE-2023-22374: A format string vulnerability exists in iControl SOAP that allows an authenticated attacker to cras A format string vulnerability exists in iControl SOAP that allows an authenticated attacker to crash the iControl SOAP CGI process or, potentially execute arbitrary code. In appliance mode BIG-IP, a successful exploit of this vulnerability can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical
cvelistv5nvd
CVE-2023-23552HIGHCVSS 7.5≥ 17.0.0, < 17.0.0.2≥ 16.1.0, < 16.1.3.3+3 more2023-02-01
CVE-2023-23552 [HIGH] CWE-400 CVE-2023-23552: On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.0 before 15.1.8, 14.1.x before 14.1 On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.0 before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a BIG-IP Advanced WAF or BIG-IP ASM security policy is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Te
cvelistv5nvd
CVE-2023-22664HIGHCVSS 7.5≥ 17.0.0, < 17.0.0.2≥ 16.1.0, < 16.1.3.32023-02-01
CVE-2023-22664 [HIGH] CWE-400 CVE-2023-22664: On BIG-IP versions 17.0.x before 17.0.0.2 and 16.1.x before 16.1.3.3, and BIG-IP SPK starting in ver On BIG-IP versions 17.0.x before 17.0.0.2 and 16.1.x before 16.1.3.3, and BIG-IP SPK starting in version 1.6.0, when a client-side HTTP/2 profile and the HTTP MRF Router option are enabled for a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support
cvelistv5nvd