F5 Big-Ip Advanced Web Application Firewall vulnerabilities
189 known vulnerabilities affecting f5/big-ip_advanced_web_application_firewall.
Total CVEs
189
CISA KEV
6
actively exploited
Public exploits
5
Exploited in wild
6
Severity breakdown
CRITICAL10HIGH116MEDIUM61LOW2
Vulnerabilities
Page 2 of 10
CVE-2024-45844P3HIGHCVSS 7.2≥ 15.1.0, < 15.1.10.5≥ 16.1.0, < 16.1.5+1 more2024-10-16
CVE-2024-45844 [HIGH] CWE-306 CVE-2024-45844: BIG-IP monitor functionality may allow an attacker to bypass access control restrictions, regardless
BIG-IP monitor functionality may allow an attacker to bypass access control restrictions, regardless of the port lockdown settings. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2025-61958P3HIGHCVSS 8.7≥ 15.1.0, < 15.1.10.8≥ 16.1.0, < 16.1.6.1+2 more2025-10-15
CVE-2025-61958 [HIGH] CWE-250 CVE-2025-61958: A vulnerability exists in the iHealth command that may allow an authenticated attacker with at least
A vulnerability exists in the iHealth command that may allow an authenticated attacker with at least a resource administrator role to bypass tmsh restrictions and gain access to a bash shell. For BIG-IP systems running in Appliance mode, a successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reache
nvd
CVE-2026-34176P3HIGHCVSS 8.7≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+2 more2026-05-13
CVE-2026-34176 [HIGH] CWE-78 CVE-2026-34176: When running in Appliance mode, an authenticated remote command injection vulnerability exists in an
When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-32673P3HIGHCVSS 8.7≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+2 more2026-05-13
CVE-2026-32673 [HIGH] CWE-250 CVE-2026-32673: A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the
A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system commands with higher privileges. In appliance mode deployments, a successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reache
nvd
CVE-2021-22990P3HIGHCVSS 7.2≥ 11.6.1, < 11.6.5.3≥ 12.1.0, < 12.1.5.3+4 more2021-03-31
CVE-2021-22990 [HIGH] CVE-2021-22990: On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x befo
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, on systems with Advanced WAF or BIG-IP ASM provisioned, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has an authenticated remote command execution v
nvd
CVE-2026-41953P3HIGHCVSS 8.7≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+2 more2026-05-13
CVE-2026-41953 [HIGH] CWE-77 CVE-2026-41953: A vulnerability exists in BIG-IP systems where a highly privileged, authenticated attacker with at l
A vulnerability exists in BIG-IP systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can modify configuration objects resulting in privilege escalation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-40631P3HIGHCVSS 8.7≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+2 more2026-05-13
CVE-2026-40631 [HIGH] CWE-552 CVE-2026-40631: An authenticated attacker with the Resource Administrator or Administrator role can modify configura
An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects through iControl SOAP resulting in privilege escalation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-32643P3HIGHCVSS 8.7≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+2 more2026-05-13
CVE-2026-32643 [HIGH] CWE-250 CVE-2026-32643: A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacke
A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-42406P3HIGHCVSS 8.7≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+2 more2026-05-13
CVE-2026-42406 [HIGH] CWE-267 CVE-2026-42406: A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacke
A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2021-23014P3HIGHCVSS 8.8≥ 14.1.0, < 14.1.4≥ 15.1.0, < 15.1.3+1 more2021-05-10
CVE-2021-23014 [HIGH] CWE-862 CVE-2021-23014: On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, and 14.1.x before 14.1.4, BIG-IP Advanced
On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, and 14.1.x before 14.1.4, BIG-IP Advanced WAF and ASM are missing authorization checks for file uploads to a specific directory within the REST API which might allow Authenticated users with guest privileges to upload files. Note: Software versions which have reached End of Technical Support (Eo
nvd
CVE-2025-53868P3HIGHCVSS 8.7≥ 15.1.0, < 15.1.10.8≥ 16.1.0, < 16.1.6.1+2 more2025-10-15
CVE-2025-53868 [HIGH] CWE-78 CVE-2025-53868: When running in Appliance mode, a highly privileged authenticated attacker with access to SCP and SF
When running in Appliance mode, a highly privileged authenticated attacker with access to SCP and SFTP may be able to bypass Appliance mode restrictions using undisclosed commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-40698P3HIGHCVSS 8.7≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+2 more2026-05-13
CVE-2026-40698 [HIGH] CWE-77 CVE-2026-40698: A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacke
A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can create SNMP configuration objects through iControl REST or the TMOS shell (tmsh) resulting in privilege escalation. Note: Software versions which have reached End of Technical Support (EoTS) are not eva
nvd
CVE-2021-23029P3HIGHCVSS 8.8≥ 16.0.0, < 16.0.1.22021-09-14
CVE-2021-23029 [HIGH] CWE-918 CVE-2021-23029: On version 16.0.x before 16.0.1.2, insufficient permission checks may allow authenticated users with
On version 16.0.x before 16.0.1.2, insufficient permission checks may allow authenticated users with guest privileges to perform Server-Side Request Forgery (SSRF) attacks through F5 Advanced Web Application Firewall (WAF) and the BIG-IP ASM Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evalu
nvd
CVE-2026-39459P3HIGHCVSS 7.2≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+2 more2026-05-13
CVE-2026-39459 [HIGH] CWE-272 CVE-2026-39459: A vulnerability exists in iControl REST and the TMOS Shell (tmsh) where a highly privileged, authent
A vulnerability exists in iControl REST and the TMOS Shell (tmsh) where a highly privileged, authenticated attacker with at least the Manager role can create configuration objects that allow running arbitrary commands.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-43746P3HIGHCVSS 8.7≥ 13.1.0, ≤ 14.1.5≥ 15.1.0, < 15.1.9+1 more2023-10-10
CVE-2023-43746 [HIGH] CWE-267 CVE-2023-43746: When running in Appliance mode, an authenticated user assigned the Administrator role may be able t
When running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing BIG-IP external monitor on a BIG-IP system. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evalua
nvd
CVE-2026-39455P3HIGHCVSS 7.5≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+2 more2026-05-13
CVE-2026-39455 [HIGH] CWE-772 CVE-2026-39455: When the BIG-IP Configuration utility is configured to use Lightweight Directory Access Protocol (LD
When the BIG-IP Configuration utility is configured to use Lightweight Directory Access Protocol (LDAP) authentication, undisclosed traffic can cause the httpd process to exhaust the available file descriptors. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2021-22974P3HIGHCVSS 7.5≥ 13.1.0, < 13.1.3.6≥ 14.1.0, < 14.1.3.1+2 more2021-02-12
CVE-2021-22974 [HIGH] CVE-2021-22974: On BIG-IP version 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, and 13.1.x b
On BIG-IP version 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, and 13.1.x before 13.1.3.6 and all versions of BIG-IQ 7.x and 6.x, an authenticated attacker with access to iControl REST over the control plane may be able to take advantage of a race condition to execute commands with an elevated privilege level. This vulnerability is du
nvd
CVE-2022-27806P3HIGHCVSS 7.2v13.1.0v13.1.1+16 more2022-05-05
CVE-2022-27806 [HIGH] CWE-77 CVE-2022-27806: On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP Advanced WAF, ASM
On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP Advanced WAF, ASM, and ASM, and F5 BIG-IP Guided Configuration (GC) all versions prior to 9.0, when running in Appliance mode, an authenticated attacker assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing command injection vulnera
nvd
CVE-2026-41218P3HIGHCVSS 7.5≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+2 more2026-05-13
CVE-2026-41218 [HIGH] CWE-416 CVE-2026-41218: When BIG-IP PEM iRules are configured on a virtual server (iRules using commands starting with CLASS
When BIG-IP PEM iRules are configured on a virtual server (iRules using commands starting with CLASSIFICATION::, CLASSIFY::, PEM::, PSC::, and the urlcatquery command), undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2025-46706P3HIGHCVSS 7.5≥ 16.1.0, < 16.1.6≥ 17.1.0, < 17.1.2.22025-10-15
CVE-2025-46706 [HIGH] CWE-770 CVE-2025-46706: When an iRule containing the HTTP::respond command is configured on a virtual server, undisclosed re
When an iRule containing the HTTP::respond command is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd