F5 Big-Ip vulnerabilities
261 known vulnerabilities affecting f5/big-ip.
Total CVEs
261
CISA KEV
4
actively exploited
Public exploits
7
Exploited in wild
5
Severity breakdown
CRITICAL9HIGH159MEDIUM88LOW5
Vulnerabilities
Page 9 of 14
CVE-2019-6629P3HIGHCVSS 7.5vBIG-IP 14.1.0-14.1.0.52019-07-03
CVE-2019-6629 [HIGH] CVE-2019-6629: On BIG-IP 14.1.0-14.1.0.5, undisclosed SSL traffic to a virtual server configured with a Client SSL
On BIG-IP 14.1.0-14.1.0.5, undisclosed SSL traffic to a virtual server configured with a Client SSL profile may cause TMM to fail and restart. The Client SSL profile must have session tickets enabled and use DHE cipher suites to be affected. This only impacts the data plane, there is no impact to the control plane.
nvd
CVE-2019-6680P3HIGHCVSS 7.5v15.0.0-15.0.1v14.1.0-14.1.2+4 more2019-12-23
CVE-2019-6680 [HIGH] CVE-2019-6680: On BIG-IP versions 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and
On BIG-IP versions 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.5.2-11.6.5, while processing traffic through a standard virtual server that targets a FastL4 virtual server (VIP on VIP), hardware appliances may stop responding.
nvd
CVE-2019-6677P3HIGHCVSS 7.5v15.0.0-15.0.1v14.1.0-14.1.2+3 more2019-12-23
CVE-2019-6677 [HIGH] CVE-2019-6677: On BIG-IP versions 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, and 12.1.0-12.1.5,
On BIG-IP versions 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, and 12.1.0-12.1.5, under certain conditions when using custom TCP congestion control settings in a TCP profile, TMM stops processing traffic when processed by an iRule.
nvd
CVE-2019-6673P3HIGHCVSS 7.5v15.0.0-15.0.1v14.0.0-14.1.22019-11-27
CVE-2019-6673 [HIGH] CVE-2019-6673: On versions 15.0.0-15.0.1 and 14.0.0-14.1.2, when the BIG-IP is configured in HTTP/2 Full Proxy mode
On versions 15.0.0-15.0.1 and 14.0.0-14.1.2, when the BIG-IP is configured in HTTP/2 Full Proxy mode, specifically crafted requests may cause a disruption of service provided by the Traffic Management Microkernel (TMM).
nvd
CVE-2024-25560P3HIGHCVSS 7.5≥ 17.1.0, < 17.1.1≥ 16.1.0, < 16.1.4+1 more2024-05-08
CVE-2024-25560 [HIGH] CWE-476 CVE-2024-25560: When BIG-IP AFM is licensed and provisioned, undisclosed DNS traffic can cause the Traffic Manageme
When BIG-IP AFM is licensed and provisioned, undisclosed DNS traffic can cause the Traffic Management Microkernel (TMM) to terminate.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2025-21091P3HIGHCVSS 7.5≥ 17.1.0, < 17.1.2≥ 16.1.0, < *+1 more2025-02-05
CVE-2025-21091 [HIGH] CWE-401 CVE-2025-21091: When SNMP v1 or v2c are disabled on the BIG-IP, undisclosed requests can cause an increase in memory
When SNMP v1 or v2c are disabled on the BIG-IP, undisclosed requests can cause an increase in memory resource utilization.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
CVE-2025-59483P3MEDIUMCVSS 6.5≥ 17.5.0, < 17.5.1.3≥ 17.1.0, < 17.1.3+2 more2025-10-15
CVE-2025-59483 [MEDIUM] CWE-73 CVE-2025-59483: A validation vulnerability exists in an undisclosed URL in the Configuration utility. Note: Softwar
A validation vulnerability exists in an undisclosed URL in the Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2019-6676P3HIGHCVSS 7.5v15.0.0-15.0.1v14.0.0-14.1.2.2+1 more2019-12-23
CVE-2019-6676 [HIGH] CVE-2019-6676: On versions 15.0.0-15.0.1, 14.0.0-14.1.2.2, and 13.1.0-13.1.3.1, TMM may restart on BIG-IP Virtual E
On versions 15.0.0-15.0.1, 14.0.0-14.1.2.2, and 13.1.0-13.1.3.1, TMM may restart on BIG-IP Virtual Edition (VE) when using virtio direct descriptors and packets 2 KB or larger.
nvd
CVE-2019-6667P3HIGHCVSS 7.5v15.0.0-15.0.1v14.1.0-14.1.0.5+4 more2019-11-27
CVE-2019-6667 [HIGH] CWE-400 CVE-2019-6667: On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.1.0-13.1.1.5, 12.1.0-12.1.4.1, and 11.
On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.1.0-13.1.1.5, 12.1.0-12.1.4.1, and 11.5.1-11.6.5, under certain conditions, TMM may consume excessive resources when processing traffic for a Virtual Server with the FIX (Financial Information eXchange) profile applied.
nvd
CVE-2025-48500P3HIGHCVSS 7.3≥ 17.5.0, < *≥ 17.1.0, < *+2 more2025-08-13
CVE-2025-48500 [HIGH] CWE-353 CVE-2025-48500: A missing file integrity check vulnerability exists on MacOS F5 VPN browser client installer that ma
A missing file integrity check vulnerability exists on MacOS F5 VPN browser client installer that may allow a local, authenticated attacker with access to the local file system to replace it with a malicious package installer.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-40462P3MEDIUMCVSS 6.5≥ 21.0.0, < 21.0.0.1≥ 17.5.0, < 17.5.1.4+2 more2026-05-13
CVE-2026-40462 [MEDIUM] CWE-732 CVE-2026-40462: Incorrect permission assignment vulnerabilities exist in iControl REST and TMOS shell (tmsh) undiscl
Incorrect permission assignment vulnerabilities exist in iControl REST and TMOS shell (tmsh) undisclosed command which may allow an authenticated attacker to view sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2019-6681P3HIGHCVSS 7.5v15.0.0-15.0.1.1v14.1.0-14.1.2+3 more2019-12-23
CVE-2019-6681 [HIGH] CWE-401 CVE-2019-6681: On BIG-IP versions 15.0.0-15.0.1.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, and 12.1.0-12.1.5
On BIG-IP versions 15.0.0-15.0.1.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, and 12.1.0-12.1.5, a memory leak in Multicast Forwarding Cache (MFC) handling in tmrouted.
nvd
CVE-2020-5856P3HIGHCVSS 7.5v15.0.0-15.0.1.1v14.1.0-14.1.2.22020-02-06
CVE-2020-5856 [HIGH] CVE-2020-5856: On BIG-IP 15.0.0-15.0.1.1 and 14.1.0-14.1.2.2, while processing specifically crafted traffic using t
On BIG-IP 15.0.0-15.0.1.1 and 14.1.0-14.1.2.2, while processing specifically crafted traffic using the default 'xnet' driver, Virtual Edition instances hosted in Amazon Web Services (AWS) may experience a TMM restart.
nvd
CVE-2019-6669P3HIGHCVSS 7.5v15.0.0-15.0.1v14.1.0-14.1.2+4 more2019-11-27
CVE-2019-6669 [HIGH] CVE-2019-6669: On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.1-11
On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.1-11.6.5.1, undisclosed traffic flow may cause TMM to restart under some circumstances.
nvd
CVE-2022-34851P3MEDIUMCVSS 6.5≥ 13.1.0, < 13.1.x*≥ 14.1.x, < 14.1.5.1+3 more2022-08-04
CVE-2022-34851 [MEDIUM] CWE-20 CVE-2022-34851: In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x be
In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, and BIG-IQ Centralized Management all versions of 8.x, an authenticated attacker may cause iControl SOAP to become unavailable through undisclosed requests. Note: Software versions which have reached End of Te
nvd
CVE-2025-47148P3MEDIUMCVSS 6.5≥ 17.5.0, < 17.5.1≥ 17.1.0, < 17.1.3+2 more2025-10-15
CVE-2025-47148 [MEDIUM] CWE-404 CVE-2025-47148: When the BIG-IP system is configured as both a Security Assertion Markup Language (SAML) service pro
When the BIG-IP system is configured as both a Security Assertion Markup Language (SAML) service provider (SP) and Identity Provider (IdP), with single logout (SLO) enabled on an access policy, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not
nvd
CVE-2026-35062P3MEDIUMCVSS 6.5≥ 21.0.0, < 21.0.0.1≥ 17.5.1, < 17.5.1.4+2 more2026-05-13
CVE-2026-35062 [MEDIUM] CWE-266 CVE-2026-35062: An authenticated iControl SOAP user may be able to obtain information of other accounts. Note: Sof
An authenticated iControl SOAP user may be able to obtain information of other accounts.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2024-31156P3HIGHCVSS 8.0≥ 17.1.0, < 17.1.2≥ 16.1.0, < 16.1.5.2+1 more2024-05-08
CVE-2024-31156 [HIGH] CWE-79 CVE-2024-31156: A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Confi
A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2019-6666P3HIGHCVSS 7.5v15.0.0-15.0.1v14.1.0-14.1.0.5+2 more2019-11-27
CVE-2019-6666 [HIGH] CVE-2019-6666: On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, and 13.1.0-13.1.1.4, the TMM process may
On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, and 13.1.0-13.1.1.4, the TMM process may produce a core file when an upstream server or cache sends the BIG-IP an invalid age header value.
nvd
CVE-2019-6641P4MEDIUMCVSS 6.5vBIG-IP 12.1.0-12.1.4.12019-07-03
CVE-2019-6641 [MEDIUM] CVE-2019-6641: On BIG-IP 12.1.0-12.1.4.1, undisclosed requests can cause iControl REST processes to crash. The atta
On BIG-IP 12.1.0-12.1.4.1, undisclosed requests can cause iControl REST processes to crash. The attack can only come from an authenticated user; all roles are capable of performing the attack. Unauthenticated users cannot perform this attack.
nvd