F5 Big-Ip Advanced Web Application Firewall vulnerabilities

154 known vulnerabilities affecting f5/big-ip_advanced_web_application_firewall.

Total CVEs
154
CISA KEV
6
actively exploited
Public exploits
4
Exploited in wild
6
Severity breakdown
CRITICAL9HIGH99MEDIUM43LOW3

Vulnerabilities

Page 3 of 8
CVE-2024-41727HIGHCVSS 8.7≥ 15.1.0, ≤ 15.1.1≥ 16.1.0, < 16.1.5+1 more2024-08-14
CVE-2024-41727 [HIGH] CWE-400 CVE-2024-41727: In BIG-IP tenants running on r2000 and r4000 series hardware, or BIG-IP Virtual Edition (VEs) using In BIG-IP tenants running on r2000 and r4000 series hardware, or BIG-IP Virtual Edition (VEs) using Intel E810 SR-IOV NIC, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2024-41723MEDIUMCVSS 5.3≥ 15.1.0, ≤ 15.1.1≥ 16.1.0, < 16.1.5+1 more2024-08-14
CVE-2024-41723 [MEDIUM] CWE-200 CVE-2024-41723: Undisclosed requests to BIG-IP iControl REST can lead to information leak of user account names.  No Undisclosed requests to BIG-IP iControl REST can lead to information leak of user account names. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2024-25560HIGHCVSS 7.5≥ 15.1.0, < 15.1.10.8≥ 16.1.0, < 16.1.4+1 more2024-05-08
CVE-2024-25560 [HIGH] CWE-476 CVE-2024-25560: When BIG-IP AFM is licensed and provisioned, undisclosed DNS traffic can cause the Traffic Manageme When BIG-IP AFM is licensed and provisioned, undisclosed DNS traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2024-31156HIGHCVSS 8.0≥ 15.1.0, < 15.1.10.4≥ 16.1.0, < 16.1.4.3+1 more2024-05-08
CVE-2024-31156 [HIGH] CWE-79 CVE-2024-31156: A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Confi A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2024-33608HIGHCVSS 7.5v17.1.02024-05-08
CVE-2024-33608 [HIGH] CWE-824 CVE-2024-33608: When IPsec is configured on a virtual server, undisclosed traffic can cause the Traffic Management M When IPsec is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2024-28889MEDIUMCVSS 5.9≥ 15.1.0, < 15.1.10.4≥ 16.1.0, < 16.1.4.3+1 more2024-05-08
CVE-2024-28889 [MEDIUM] CWE-825 CVE-2024-28889: When an SSL profile with alert timeout is configured with a non-default value on a virtual server When an SSL profile with alert timeout is configured with a non-default value on a virtual server, undisclosed traffic along with conditions beyond the attacker's control can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2024-32761MEDIUMCVSS 6.5≥ 15.1.0, < 15.1.102024-05-08
CVE-2024-32761 [MEDIUM] CWE-119 CVE-2024-32761: Under certain conditions, a data leak may occur in the Traffic Management Microkernels (TMMs) of BIG Under certain conditions, a data leak may occur in the Traffic Management Microkernels (TMMs) of BIG-IP tenants running on VELOS and rSeries platforms. This leak occurs randomly and cannot be deliberately triggered. If it occurs, it may leak up to 64 bytes of non-contiguous randomized bytes. Under rare conditions, this may lead to a TMM restart, aff
nvd
CVE-2024-33604MEDIUMCVSS 6.1≥ 15.1.0, < 15.1.10.4≥ 16.1.0, < 16.1.4.3+1 more2024-05-08
CVE-2024-33604 [MEDIUM] CWE-79 CVE-2024-33604: A reflected cross-site scripting (XSS) vulnerability exist in undisclosed page of the BIG-IP Config A reflected cross-site scripting (XSS) vulnerability exist in undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
CVE-2024-27202MEDIUMCVSS 4.7≥ 15.1.0, < 15.1.10.4≥ 16.1.0, < 16.1.4.3+1 more2024-05-08
CVE-2024-27202 [MEDIUM] CWE-79 CVE-2024-27202: A DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Co A DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2024-21849HIGHCVSS 7.5≥ 16.1.0, < 16.1.42024-02-14
CVE-2024-21849 [HIGH] CWE-466 CVE-2024-21849: When an Advanced WAF/ASM security policy and a Websockets profile are configured on a virtual ser When an Advanced WAF/ASM security policy and a Websockets profile are configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2024-23805HIGHCVSS 7.5≥ 15.1.0, < 15.1.10≥ 16.1.0, < 16.1.4+1 more2024-02-14
CVE-2024-23805 [HIGH] CWE-131 CVE-2024-23805: Undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. For the Appli Undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. For the Application Visibility and Reporting module, this may occur when the HTTP Analytics profile with URLs enabled under Collected Entities is configured on a virtual server and the DB variables avr.IncludeServerInURI or avr.CollectOnlyHostnameFromURI are enabled.
nvd
CVE-2024-23308HIGHCVSS 7.5≥ 17.1.0, < 17.1.12024-02-14
CVE-2024-23308 [HIGH] CWE-476 CVE-2024-23308: When a BIG-IP Advanced WAF or BIG-IP ASM policy with a Request Body Handling option is attached to When a BIG-IP Advanced WAF or BIG-IP ASM policy with a Request Body Handling option is attached to a virtual server, undisclosed requests can cause the BD process to terminate. The condition results from setting the Request Body Handling option in the Header-Based Content Profile for an Allowed URL with "Apply value and content signatures and detect th
nvd
CVE-2024-21789HIGHCVSS 7.5≥ 17.1.0, < 17.1.12024-02-14
CVE-2024-21789 [HIGH] CWE-772 CVE-2024-21789: When a BIG-IP ASM/Advanced WAF security policy is configured on a virtual server, undisclosed req When a BIG-IP ASM/Advanced WAF security policy is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
CVE-2024-23603LOWCVSS 3.8≥ 15.1.0, < 15.1.10≥ 16.1.0, < 16.1.4+1 more2024-02-14
CVE-2024-23603 [LOW] CWE-89 CVE-2024-23603: An SQL injection vulnerability exists in an undisclosed page of the BIG-IP Configuration utility. An SQL injection vulnerability exists in an undisclosed page of the BIG-IP Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
CVE-2023-46747CRITICALCVSS 9.8KEVPoC≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, ≤ 14.1.5+3 more2023-10-26
CVE-2023-46747 [CRITICAL] CWE-288 CVE-2023-46747: Undisclosed requests may bypass configuration utility authentication, allowing an attacker with netw Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
CVE-2023-46748HIGHCVSS 8.8KEV≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, ≤ 14.1.5+3 more2023-10-26
CVE-2023-46748 [HIGH] CWE-89 CVE-2023-46748: An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) a
nvd
CVE-2023-41373CRITICALCVSS 9.9≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, < 14.1.5.6+3 more2023-10-10
CVE-2023-41373 [CRITICAL] CWE-22 CVE-2023-41373: A directory traversal vulnerability exists in the BIG-IP Configuration Utility that may allow an au A directory traversal vulnerability exists in the BIG-IP Configuration Utility that may allow an authenticated attacker to execute commands on the BIG-IP system. For BIG-IP system running in Appliance mode, a successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support
nvd
CVE-2023-41085HIGHCVSS 7.5≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, ≤ 14.1.5+2 more2023-10-10
CVE-2023-41085 [HIGH] CWE-755 CVE-2023-41085: When IPSec is configured on a Virtual Server, undisclosed traffic can cause TMM to terminate.  Not When IPSec is configured on a Virtual Server, undisclosed traffic can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-44487HIGHCVSS 7.5KEVPoC≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, ≤ 14.1.5+3 more2023-10-10
CVE-2023-44487 [HIGH] CWE-400 CVE-2023-44487: The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancell The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
nvd
CVE-2023-42768HIGHCVSS 7.2≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, ≤ 14.1.5+2 more2023-10-10
CVE-2023-42768 [HIGH] CWE-613 CVE-2023-42768: When a non-admin user has been assigned an administrator role via an iControl REST PUT request and When a non-admin user has been assigned an administrator role via an iControl REST PUT request and later the user's role is reverted back to a non-admin role via the Configuration utility, tmsh, or iControl REST. BIG-IP non-admin user can still have access to iControl REST admin resource. Note: Software versions which have reached End of Technical Supp
nvd