F5 Big-Ip Advanced Web Application Firewall vulnerabilities
189 known vulnerabilities affecting f5/big-ip_advanced_web_application_firewall.
Total CVEs
189
CISA KEV
6
actively exploited
Public exploits
5
Exploited in wild
6
Severity breakdown
CRITICAL10HIGH116MEDIUM61LOW2
Vulnerabilities
Page 9 of 10
CVE-2025-54500P4MEDIUMCVSS 5.3≥ 15.1.0, < 15.1.10.8≥ 16.1.0, < 16.1.6.1+2 more2025-08-13
CVE-2025-54500 [MEDIUM] CWE-770 CVE-2025-54500: An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control fr
An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit (HTTP/2 MadeYouReset Attack).
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2022-23031P4MEDIUMCVSS 4.9≥ 14.1.0, ≤ 14.1.4≥ 15.1.0, ≤ 15.1.3+1 more2022-01-25
CVE-2022-23031 [MEDIUM] CWE-611 CVE-2022-23031: On BIG-IP FPS, ASM, and Advanced WAF versions 16.1.x before 16.1.1, 15.1.x before 15.1.4, and 14.1.x
On BIG-IP FPS, ASM, and Advanced WAF versions 16.1.x before 16.1.1, 15.1.x before 15.1.4, and 14.1.x before 14.1.4.4, an XML External Entity (XXE) vulnerability exists in an undisclosed page of the F5 Advanced Web Application Firewall (Advanced WAF) and BIG-IP ASM Traffic Management User Interface (TMUI), also referred to as the Configuration utilit
nvd
CVE-2026-42063P4MEDIUMCVSS 4.9≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+2 more2026-05-13
CVE-2026-42063 [MEDIUM] CWE-552 CVE-2026-42063: A vulnerability exists in iControl SOAP where an authenticated attacker with the Resource Administra
A vulnerability exists in iControl SOAP where an authenticated attacker with the Resource Administrator or Administrator role can download sensitive files. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-42781P4MEDIUMCVSS 6.5v21.0.0≥ 17.1.0, ≤ 17.1.3+1 more2026-05-13
CVE-2026-42781 [MEDIUM] CWE-835 CVE-2026-42781: When embedded Packet Velocity Acceleration (ePVA) acceleration is configured, undisclosed local ethe
When embedded Packet Velocity Acceleration (ePVA) acceleration is configured, undisclosed local ethernet traffic can cause an increase in ePVA and Traffic Management Microkernel (TMM) resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2021-23027P4MEDIUMCVSS 6.1≥ 14.1.0, ≤ 14.1.4≥ 15.1.0, ≤ 15.1.3+1 more2021-09-14
CVE-2021-23027 [MEDIUM] CWE-79 CVE-2021-23027: On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, and 14.1.x before 14.1.4.3, a DOM based c
On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, and 14.1.x before 14.1.4.3, a DOM based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to execute JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Te
nvd
CVE-2021-23053P4MEDIUMCVSS 5.3≥ 13.1.0, < 13.1.3.6≥ 14.1.0, < 14.1.3.1+1 more2021-09-14
CVE-2021-23053 [MEDIUM] CWE-400 CVE-2021-23053: On version 15.1.x before 15.1.3, 14.1.x before 14.1.3.1, and 13.1.x before 13.1.3.6, when the brute
On version 15.1.x before 15.1.3, 14.1.x before 14.1.3.1, and 13.1.x before 13.1.3.6, when the brute force protection feature of BIG-IP Advanced WAF or BIG-IP ASM is enabled on a virtual server and the virtual server is under brute force attack, the MySQL database may run out of disk space due to lack of row limit on undisclosed tables in the MYSQL da
nvd
CVE-2026-41954P4MEDIUMCVSS 4.9≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+2 more2026-05-13
CVE-2026-41954 [MEDIUM] CWE-200 CVE-2026-41954: Sensitive information disclosure vulnerability exists in the undisclosed iControl REST endpoint and
Sensitive information disclosure vulnerability exists in the undisclosed iControl REST endpoint and TMOS Shell (tmsh) command which may allow an authenticated attacker with resource administrator role privileges to view sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2020-27719P4MEDIUMCVSS 6.1≥ 14.1.0, < 14.1.3.1≥ 15.0.0, < 15.1.1+1 more2020-12-24
CVE-2020-27719 [MEDIUM] CWE-79 CVE-2020-27719: On BIG-IP 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.3, a cross-site scripting (XSS) vulnerab
On BIG-IP 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.3, a cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility.
nvd
CVE-2024-33604P4MEDIUMCVSS 6.1≥ 15.1.0, < 15.1.10.4≥ 16.1.0, < 16.1.4.3+1 more2024-05-08
CVE-2024-33604 [MEDIUM] CWE-79 CVE-2024-33604: A reflected cross-site scripting (XSS) vulnerability exist in undisclosed page of the BIG-IP Config
A reflected cross-site scripting (XSS) vulnerability exist in undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
CVE-2023-27378P4MEDIUMCVSS 6.1≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, < 14.1.5.4+3 more2023-05-03
CVE-2023-27378 [MEDIUM] CWE-79 CVE-2023-27378: Multiple reflected cross-site scripting (XSS) vulnerabilities exist in undisclosed pages of the BIG
Multiple reflected cross-site scripting (XSS) vulnerabilities exist in undisclosed pages of the BIG-IP Configuration utility which allow an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-38138P4MEDIUMCVSS 6.1≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, < 14.1.5.5+3 more2023-08-02
CVE-2023-38138 [MEDIUM] CWE-79 CVE-2023-38138: A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Co
A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-24594P4MEDIUMCVSS 5.3v14.1.5v15.1.4.1+1 more2023-05-03
CVE-2023-24594 [MEDIUM] CWE-400 CVE-2023-24594: When an SSL profile is configured on a Virtual Server, undisclosed traffic can cause an increase in
When an SSL profile is configured on a Virtual Server, undisclosed traffic can cause an increase in CPU or SSL accelerator resource utilization.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-38423P4MEDIUMCVSS 5.4≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, < 14.1.5.5+3 more2023-08-02
CVE-2023-38423 [MEDIUM] CWE-79 CVE-2023-38423: A cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuratio
A cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-43485P4MEDIUMCVSS 5.5≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, ≤ 14.1.5+2 more2023-10-10
CVE-2023-43485 [MEDIUM] CWE-532 CVE-2023-43485: When TACACS+ audit forwarding is configured on BIG-IP or BIG-IQ system, sharedsecret is logged in p
When TACACS+ audit forwarding is configured on BIG-IP or BIG-IQ system, sharedsecret is logged in plaintext in the audit log. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-40703P4MEDIUMCVSS 5.4≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+1 more2026-05-13
CVE-2026-40703 [MEDIUM] CWE-352 CVE-2026-40703: A cross-site request forgery (CSRF) vulnerability exists in the dashboard of the BIG-IP Configuratio
A cross-site request forgery (CSRF) vulnerability exists in the dashboard of the BIG-IP Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-28406P4MEDIUMCVSS 4.3≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, < 14.1.5.4+3 more2023-05-03
CVE-2023-28406 [MEDIUM] CWE-22 CVE-2023-28406: A directory traversal vulnerability exists in an undisclosed page of the BIG-IP Configuration utilit
A directory traversal vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which may allow an authenticated attacker to read files with .xml extension. Access to restricted information is limited and the attacker does not control what information is obtained.
Note: Software versions which have reached End of Technical Sup
nvd
CVE-2021-23001P4MEDIUMCVSS 4.3≥ 11.6.1, < 11.6.5.3≥ 12.1.0, < 12.1.5.3+4 more2021-03-31
CVE-2021-23001 [MEDIUM] CWE-434 CVE-2021-23001: On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1
On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, the upload functionality in BIG-IP Advanced WAF and BIG-IP ASM allows an authenticated user to upload files to the BIG-IP system using a call to an undisclosed iControl REST endpoint. Note: Sof
nvd
CVE-2021-22981P4MEDIUMCVSS 4.8≥ 11.6.1, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.52021-02-12
CVE-2021-22981 [MEDIUM] CVE-2021-22981: On all versions of BIG-IP 12.1.x and 11.6.x, the original TLS protocol includes a weakness in the ma
On all versions of BIG-IP 12.1.x and 11.6.x, the original TLS protocol includes a weakness in the master secret negotiation that is mitigated by the Extended Master Secret (EMS) extension defined in RFC 7627. TLS connections that do not use EMS are vulnerable to man-in-the-middle attacks during renegotiation. Note: Software versions which have reached End o
nvd
CVE-2022-23026P4MEDIUMCVSS 4.3≥ 12.1.0, ≤ 12.1.6≥ 13.1.0, ≤ 13.1.4+3 more2022-01-25
CVE-2022-23026 [MEDIUM] CWE-434 CVE-2022-23026: On BIG-IP ASM & Advanced WAF version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.
On BIG-IP ASM & Advanced WAF version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versions of 13.1.x and 12.1.x, an authenticated user with low privileges, such as a guest, can upload data using an undisclosed REST endpoint causing an increase in disk resource utilization. Note: Software versions which have reached E
nvd
CVE-2024-27202P4MEDIUMCVSS 4.7≥ 15.1.0, < 15.1.10.4≥ 16.1.0, < 16.1.4.3+1 more2024-05-08
CVE-2024-27202 [MEDIUM] CWE-79 CVE-2024-27202: A DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Co
A DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd