cbcvebase.

F5 Big-Ip Advanced Firewall Manager vulnerabilities

546 known vulnerabilities affecting f5/big-ip_advanced_firewall_manager.

Total CVEs
546
CISA KEV
11
actively exploited
Public exploits
19
Exploited in wild
15
Severity breakdown
CRITICAL40HIGH303MEDIUM199LOW4

Vulnerabilities

Page 7 of 28
CVE-2019-6611P3HIGHCVSS 7.5≥ 11.5.2, < 11.5.9≥ 11.6.1, < 11.6.4+3 more2019-05-03
CVE-2019-6611 [HIGH] CVE-2019-6611: When BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8 are When BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8 are processing certain rare data sequences occurring in PPTP VPN traffic, the BIG-IP system may execute incorrect logic. The TMM may restart and produce a core file as a result of this condition. The BIG-IP system provisioned with the CGNAT module and configured with
nvd
CVE-2019-6621P3HIGHCVSS 7.2≥ 11.5.2, < 11.5.9≥ 11.6.1, < 11.6.4+4 more2019-07-02
CVE-2019-6621 [HIGH] CWE-78 CVE-2019-6621: On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4.1, 11.6.1-11.6.3.4, and 1 On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4.1, 11.6.1-11.6.3.4, and 11.5.2-11.5.8 and BIG-IQ 7.0.0-7.1.0.2, 6.0.0-6.1.0, and 5.1.0-5.4.0, an undisclosed iControl REST worker is vulnerable to command injection by an admin/resource admin user. This issue impacts both iControl REST and tmsh implementations.
nvd
CVE-2019-6685P3HIGHCVSS 7.8≥ 11.5.2, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.5+4 more2019-12-23
CVE-2019-6685 [HIGH] CWE-269 CVE-2019-6685: On BIG-IP versions 15.0.0-15.0.1.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, On BIG-IP versions 15.0.0-15.0.1.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, users with access to edit iRules are able to create iRules which can lead to an elevation of privilege, configuration modification, and arbitrary system command execution.
nvd
CVE-2019-6620P3HIGHCVSS 7.2≥ 11.5.2, ≤ 11.6.4≥ 12.1.0, ≤ 12.1.4+2 more2019-07-02
CVE-2019-6620 [HIGH] CWE-78 CVE-2019-6620: On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.5, 13.0.0-13.1.1.4, 12.1.0-12.1.4.1, and 11.5.1-11.6.4 and On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.5, 13.0.0-13.1.1.4, 12.1.0-12.1.4.1, and 11.5.1-11.6.4 and BIG-IQ 6.0.0-6.1.0 and 5.1.0-5.4.0, an undisclosed iControl REST worker vulnerable to command injection for an Administrator user.
nvd
CVE-2021-23048P3HIGHCVSS 7.5≥ 11.6.1, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.6+4 more2021-09-14
CVE-2021-23048 [HIGH] CWE-20 CVE-2021-23048: On BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, 13.1.x bef On BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, 13.1.x before 13.1.4.1, and all versions of 12.1.x and 11.6.x, when GPRS Tunneling Protocol (GTP) iRules commands or a GTP profile is configured on a virtual server, undisclosed GTP messages can cause the Traffic Management Microkernel (TMM) to terminate. Note: So
nvd
CVE-2021-23039P3HIGHCVSS 7.5≥ 12.1.0, ≤ 12.1.6≥ 13.1.0, ≤ 13.1.4+3 more2021-09-14
CVE-2021-23039 [HIGH] CWE-20 CVE-2021-23039: On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.2.8, and all versions of On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.2.8, and all versions of 13.1.x and 12.1.x, when IPSec is configured on a BIG-IP system, undisclosed requests from an authorized remote (IPSec) peer, which already has a negotiated Security Association, can cause the Traffic Management Microkernel (TMM) to terminate. Note: Soft
nvd
CVE-2021-23042P3HIGHCVSS 7.5≥ 12.1.0, < 12.1.6≥ 13.1.0, < 13.1.4+3 more2021-09-14
CVE-2021-23042 [HIGH] CWE-400 CVE-2021-23042: On BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before On BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before 13.1.4, and 12.1.x before 12.1.6, when an HTTP profile is configured on a virtual server, undisclosed requests can cause a significant increase in system resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are
nvd
CVE-2022-34844P3HIGHCVSS 7.5≥ 15.1.0, < 15.1.6.1≥ 16.1.0, < 16.1.3.12022-08-04
CVE-2022-34844 [HIGH] CWE-20 CVE-2022-34844: In BIG-IP Versions 16.1.x before 16.1.3.1 and 15.1.x before 15.1.6.1, and all versions of BIG-IQ 8.x In BIG-IP Versions 16.1.x before 16.1.3.1 and 15.1.x before 15.1.6.1, and all versions of BIG-IQ 8.x, when the Data Plane Development Kit (DPDK)/Elastic Network Adapter (ENA) driver is used with BIG-IP or BIG-IQ on Amazon Web Services (AWS) systems, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Successful exploita
nvd
CVE-2022-41833P3HIGHCVSS 7.5≥ 13.1.0, ≤ 13.1.52022-10-19
CVE-2022-41833 [HIGH] CWE-400 CVE-2022-41833: In all BIG-IP 13.1.x versions, when an iRule containing the HTTP::collect command is configured on a In all BIG-IP 13.1.x versions, when an iRule containing the HTTP::collect command is configured on a virtual server, undisclosed requests can cause Traffic Management Microkernel (TMM) to terminate.
nvd
CVE-2025-58071P3HIGHCVSS 7.5≥ 15.1.0, < 15.1.10.8≥ 16.1.0, < 16.1.6+2 more2025-10-15
CVE-2025-58071 [HIGH] CWE-457 CVE-2025-58071: When IPsec is configured on the BIG-IP system, undisclosed traffic can cause the Traffic Management When IPsec is configured on the BIG-IP system, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2025-59478P3HIGHCVSS 7.5≥ 15.1.0, < 15.1.10.8≥ 17.1.0, < 17.1.3+1 more2025-10-15
CVE-2025-59478 [HIGH] CWE-824 CVE-2025-59478: When a BIG-IP AFM denial-of-service (DoS) protection profile is configured on a virtual server, undi When a BIG-IP AFM denial-of-service (DoS) protection profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-40629P3HIGHCVSS 7.5≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+1 more2026-05-13
CVE-2026-40629 [HIGH] CWE-770 CVE-2026-40629: When SSL profiles are configured on a virtual server, undisclosed traffic can cause the virtual serv When SSL profiles are configured on a virtual server, undisclosed traffic can cause the virtual server to stop processing new client connections. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-40618P3HIGHCVSS 7.5≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+2 more2026-05-13
CVE-2026-40618 [HIGH] CWE-131 CVE-2026-40618: When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel Q When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel QuickAssist Technology (QAT) or on BIG-IP hardware platforms with the database variable crypto.hwacceleration set to disabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reache
nvd
CVE-2026-40423P3HIGHCVSS 7.5≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+2 more2026-05-13
CVE-2026-40423 [HIGH] CWE-770 CVE-2026-40423: When a SIP profile is configured on a virtual server, undisclosed traffic can cause the Traffic Mana When a SIP profile is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2021-23037P3CRITICALCVSS 9.6≥ 11.6.0, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.6+4 more2021-09-14
CVE-2021-23037 [CRITICAL] CWE-79 CVE-2021-23037: On all versions of 16.1.x, 16.0.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x, a reflected cross-sit On all versions of 16.1.x, 16.0.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x, a reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to execute JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technica
nvd
CVE-2015-4047P3HIGHCVSS 7.8≥ 11.3.0, ≤ 11.6.4≥ 12.0.0, ≤ 12.1.4+1 more2015-05-29
CVE-2015-4047 [HIGH] CWE-476 CVE-2015-4047: racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL poin racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a series of crafted UDP requests.
nvd
CVE-2022-28716P3HIGHCVSS 8.8≥ 11.6.1, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.6+4 more2022-05-05
CVE-2022-28716 [HIGH] CWE-79 CVE-2022-28716: On 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14 On 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x 11.6.x, a DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP AFM, CGNAT, and PEM Configuration utility that allows an attacker to execute Java
nvd
CVE-2020-5922P3HIGHCVSS 8.8≥ 11.6.1, ≤ 11.6.5≥ 12.1.0, < 12.1.5.2+3 more2020-08-26
CVE-2020-5922 [HIGH] CWE-352 CVE-2020-5922: In BIG-IP versions 15.0.0-15.1.0.4, 14.1.0-14.1.2.6, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11 In BIG-IP versions 15.0.0-15.1.0.4, 14.1.0-14.1.2.6, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2, iControl REST does not implement Cross Site Request Forgery protections for users which make use of Basic Authentication in a web browser.
nvd
CVE-2016-5736P3HIGHCVSS 7.5v11.4.0v11.4.1+7 more2016-08-19
CVE-2016-5736 [HIGH] CWE-284 CVE-2016-5736: The default configuration of the IPsec IKE peer listener in F5 BIG-IP LTM, Analytics, APM, ASM, and The default configuration of the IPsec IKE peer listener in F5 BIG-IP LTM, Analytics, APM, ASM, and Link Controller 11.2.1 before HF16, 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.6.1, and 12.x before 12.0.0 HF2; BIG-IP AAM, AFM, and PEM 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.6.1, and 12.x before 12.0.0 HF2; BIG-IP DNS 12.x before 12.0
nvd
CVE-2020-5888P3HIGHCVSS 8.1≥ 14.1.0, < 14.1.2.4≥ 15.0.0, < 15.0.1.3+1 more2020-04-30
CVE-2020-5888 [HIGH] CVE-2020-5888: On versions 15.1.0-15.1.0.1, 15.0.0-15.0.1.2, and 14.1.0-14.1.2.3, BIG-IP Virtual Edition (VE) may e On versions 15.1.0-15.1.0.1, 15.0.0-15.0.1.2, and 14.1.0-14.1.2.3, BIG-IP Virtual Edition (VE) may expose a mechanism for adjacent network (layer 2) attackers to access local daemons and bypass port lockdown settings.
nvd
F5 Big-Ip Advanced Firewall Manager vulnerabilities | cvebase