cbcvebase.

F5 Big-Ip vulnerabilities

261 known vulnerabilities affecting f5/big-ip.

Total CVEs
261
CISA KEV
4
actively exploited
Public exploits
7
Exploited in wild
5
Severity breakdown
CRITICAL9HIGH159MEDIUM88LOW5

Vulnerabilities

Page 8 of 14
CVE-2023-22664P3HIGHCVSS 7.5≥ 17.0.0, < 17.0.0.2≥ 16.1.0, < 16.1.3.32023-02-01
CVE-2023-22664 [HIGH] CWE-400 CVE-2023-22664: On BIG-IP versions 17.0.x before 17.0.0.2 and 16.1.x before 16.1.3.3, and BIG-IP SPK starting in ver On BIG-IP versions 17.0.x before 17.0.0.2 and 16.1.x before 16.1.3.3, and BIG-IP SPK starting in version 1.6.0, when a client-side HTTP/2 profile and the HTTP MRF Router option are enabled for a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support
nvd
CVE-2024-23805P3HIGHCVSS 7.5≥ 17.1.0, < 17.1.1≥ 16.1.0, < 16.1.4+1 more2024-02-14
CVE-2024-23805 [HIGH] CWE-131 CVE-2024-23805: Undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. For the Appli Undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. For the Application Visibility and Reporting module, this may occur when the HTTP Analytics profile with URLs enabled under Collected Entities is configured on a virtual server and the DB variables avr.IncludeServerInURI or avr.CollectOnlyHostnameFromURI are enabled.
nvd
CVE-2023-41085P3HIGHCVSS 7.5≥ 16.1.0, < 16.1.4≥ 15.1.0, < 15.1.9+2 more2023-10-10
CVE-2023-41085 [HIGH] CWE-755 CVE-2023-41085: When IPSec is configured on a Virtual Server, undisclosed traffic can cause TMM to terminate. Not When IPSec is configured on a Virtual Server, undisclosed traffic can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2025-24326P3HIGHCVSS 7.5≥ 17.1.0, < 17.1.2≥ 16.1.0, < 16.1.5+1 more2025-02-05
CVE-2025-24326 [HIGH] CWE-787 CVE-2025-24326: When BIG-IP Advanced WAF/ASM Behavioral DoS (BADoS) TLS Signatures feature is configured, undisclose When BIG-IP Advanced WAF/ASM Behavioral DoS (BADoS) TLS Signatures feature is configured, undisclosed traffic can case an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2025-22846P3HIGHCVSS 7.5≥ 17.1.0, < 17.1.2≥ 16.1.0, < 16.1.5+1 more2025-02-05
CVE-2025-22846 [HIGH] CWE-404 CVE-2025-22846: When SIP Session and Router ALG profiles are configured on a Message Routing type virtual server, un When SIP Session and Router ALG profiles are configured on a Message Routing type virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2025-61990P3HIGHCVSS 7.5≥ 17.5.0, < 17.5.1.3≥ 17.1.0, < 17.1.3+2 more2025-10-15
CVE-2025-61990 [HIGH] CWE-415 CVE-2025-61990: When using a multi-bladed platform with more than one blade, undisclosed traffic can cause the Traff When using a multi-bladed platform with more than one blade, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-2507P3HIGHCVSS 7.5≥ 17.5.1.4, < *2026-02-18
CVE-2026-2507 [HIGH] CWE-476 CVE-2026-2507: When BIG-IP AFM or BIG-IP DDoS is provisioned, undisclosed traffic can cause TMM to terminate. Note When BIG-IP AFM or BIG-IP DDoS is provisioned, undisclosed traffic can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-42919P3MEDIUMCVSS 6.7≥ 21.0.0, < 21.0.0.1≥ 17.5.0, < 17.5.1.4+2 more2026-05-13
CVE-2026-42919 [MEDIUM] CWE-121 CVE-2026-42919: A vulnerability exists in BIG-IP systems that may allow an authenticated attacker with administrativ A vulnerability exists in BIG-IP systems that may allow an authenticated attacker with administrative access to escalate their privileges. A successful exploit may allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-40699P3MEDIUMCVSS 6.5≥ 21.0.0, < 21.0.0.1≥ 17.5.0, < 17.5.1.4+2 more2026-05-13
CVE-2026-40699 [MEDIUM] CWE-643 CVE-2026-40699: A vulnerability exists in the undisclosed pages in the Configuration utility that may allow a low-pr A vulnerability exists in the undisclosed pages in the Configuration utility that may allow a low-privileged authenticated attacker to access to undisclosed sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-42937P3MEDIUMCVSS 6.5≥ 21.0.0, < 21.0.0.2≥ 17.5.0, < 17.5.1.6+2 more2026-05-13
CVE-2026-42937 [MEDIUM] CWE-732 CVE-2026-42937: Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) arp and Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) arp and ndp commands, and in BIG-IP iControl REST. These vulnerabilities may allow an authenticated attacker to view adjacent network information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2019-6631P3HIGHCVSS 7.5vBIG-IP 11.5.1-11.6.42019-07-03
CVE-2019-6631 [HIGH] CVE-2019-6631: On BIG-IP 11.5.1-11.6.4, iRules performing HTTP header manipulation may cause an interruption to ser On BIG-IP 11.5.1-11.6.4, iRules performing HTTP header manipulation may cause an interruption to service when processing traffic handled by a Virtual Server with an associated HTTP profile, in specific circumstances, when the requests do not strictly conform to RFCs.
nvd
CVE-2022-41624P3HIGHCVSS 7.5≥ 17.0.x, < 17.0.0.1≥ 16.1.x, < 16.1.3.2+3 more2022-10-19
CVE-2022-41624 [HIGH] CWE-401 CVE-2022-41624: In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.2, 15.1.x before 15.1.7, 14.1.x befo In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.2, 15.1.x before 15.1.7, 14.1.x before 14.1.5.2, and 13.1.x before 13.1.5.1, when a sideband iRule is configured on a virtual server, undisclosed traffic can cause an increase in memory resource utilization.
nvd
CVE-2022-41832P3HIGHCVSS 7.5≥ 17.0.x, < 17.0.0.1≥ 16.1.x, < 16.1.3.1+3 more2022-10-19
CVE-2022-41832 [HIGH] CWE-401 CVE-2022-41832: In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x be In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and 13.1.x before 13.1.5.1, when a SIP profile is configured on a virtual server, undisclosed messages can cause an increase in memory resource utilization.
nvd
CVE-2023-29163P3HIGHCVSS 7.5≥ 17.0.0, < *≥ 16.1.2.2, < 16.1.3.4+2 more2023-05-03
CVE-2023-29163 [HIGH] CWE-401 CVE-2023-29163: When UDP profile with idle timeout set to immediate or the value 0 is configured on a virtual serve When UDP profile with idle timeout set to immediate or the value 0 is configured on a virtual server, undisclosed traffic can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2024-21771P3HIGHCVSS 7.5≥ 17.1.0, < 17.1.1≥ 16.1.0, < 16.1.4+1 more2024-02-14
CVE-2024-21771 [HIGH] CWE-770 CVE-2024-21771: For unspecified traffic patterns, BIG-IP AFM IPS engine may spend an excessive amount of time match For unspecified traffic patterns, BIG-IP AFM IPS engine may spend an excessive amount of time matching the traffic against signatures, resulting in Traffic Management Microkernel (TMM) restarting and traffic disruption. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
CVE-2024-41727P3HIGHCVSS 7.5≥ 16.1.0, < 16.1.5≥ 15.1.0, < *2024-08-14
CVE-2024-41727 [HIGH] CWE-400 CVE-2024-41727: In BIG-IP tenants running on r2000 and r4000 series hardware, or BIG-IP Virtual Edition (VEs) using In BIG-IP tenants running on r2000 and r4000 series hardware, or BIG-IP Virtual Edition (VEs) using Intel E810 SR-IOV NIC, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2025-20045P3HIGHCVSS 7.5≥ 17.1.0, < 17.1.2≥ 16.1.0, < 16.1.5+1 more2025-02-05
CVE-2025-20045 [HIGH] CWE-476 CVE-2025-20045: When SIP session Application Level Gateway mode (ALG) profile with Passthru Mode enabled and SIP rou When SIP session Application Level Gateway mode (ALG) profile with Passthru Mode enabled and SIP router ALG profile are configured on a Message Routing type virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2025-41430P3HIGHCVSS 7.5≥ 17.5.0, < 17.5.1≥ 17.1.0, < 17.1.3+2 more2025-10-15
CVE-2025-41430 [HIGH] CWE-770 CVE-2025-41430: When BIG-IP SSL Orchestrator is enabled, undisclosed traffic can cause the Traffic Management Microk When BIG-IP SSL Orchestrator is enabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-41219P3MEDIUMCVSS 6.5≥ 17.5.0, < 17.5.1.4≥ 17.1.0, < 17.1.3.1+1 more2026-05-13
CVE-2026-41219 [MEDIUM] CWE-532 CVE-2026-41219: An improper sanitization vulnerability exists in the BIG-IP QKView utility that allows a low-privile An improper sanitization vulnerability exists in the BIG-IP QKView utility that allows a low-privileged attacker to read sensitive information from a QKView file. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
CVE-2019-6624P3HIGHCVSS 7.5vBIG-IP 14.1.0-14.1.0.5v14.0.0-14.0.0.4+2 more2019-07-02
CVE-2019-6624 [HIGH] CVE-2019-6624: On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, and 12.1.0-12.1.4, an undisclosed traff On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, and 12.1.0-12.1.4, an undisclosed traffic pattern sent to a BIG-IP UDP virtual server may lead to a denial-of-service (DoS).
nvd
F5 Big-Ip vulnerabilities | cvebase