F5 Big-Ip Apm vulnerabilities
520 known vulnerabilities affecting f5/big-ip_apm.
Total CVEs
520
CISA KEV
7
actively exploited
Public exploits
8
Exploited in wild
6
Severity breakdown
CRITICAL26HIGH288MEDIUM198LOW8
Vulnerabilities
Page 5 of 26
CVE-2023-41964MEDIUMCVSS 4.32023-10-10
CVE-2023-41964 [MEDIUM] CWE-312 CVE-2023-41964: The BIG-IP and BIG-IQ systems do not encrypt some sensitive information written to Database (DB) variables
CVE-2023-41964: The BIG-IP and BIG-IQ systems do not encrypt some sensitive information written to Database (DB) variables
The BIG-IP and BIG-IQ systems do not encrypt some sensitive information written to Database (DB) variables.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Product
f5
CVE-2023-39447MEDIUMCVSS 4.42023-10-10
CVE-2023-39447 [MEDIUM] CWE-532 CVE-2023-39447: When BIG-IP APM Guided Configurations are configured, undisclosed sensitive information may be logged in restnoded log
CVE-2023-39447: When BIG-IP APM Guided Configurations are configured, undisclosed sensitive information may be logged in restnoded log
When BIG-IP APM Guided Configurations are configured, undisclosed sensitive information may be logged in restnoded log.
Note: Software versions which have reached End of Technical Support (EoTS)
f5
CVE-2023-45219MEDIUMCVSS 4.42023-10-10
CVE-2023-45219 [MEDIUM] CWE-200 CVE-2023-45219: Exposure of Sensitive Information vulnerability exist in an undisclosed BIG-IP TMOS shell (tmsh) command which may al...
CVE-2023-45219: Exposure of Sensitive Information vulnerability exist in an undisclosed BIG-IP TMOS shell (tmsh) command which may al...
Exposure of Sensitive Information vulnerability exist in an undisclosed BIG-IP TMOS shell (tmsh) command which may allow an authenticated attacker with resource administrator role privileges t
f5
CVE-2023-43125MEDIUMCVSS 6.82023-09-27
CVE-2023-43125 [MEDIUM] CWE-319 CVE-2023-43125: BIG-IP APM clients may send IP traffic outside of the VPN tunnel
CVE-2023-43125: BIG-IP APM clients may send IP traffic outside of the VPN tunnel
BIG-IP APM clients may send IP traffic outside of the VPN tunnel. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Affected Products: BIG-IP APM, Big-Ip Access Policy Manager Client
Affected Versions: 13.1.5.1; 14.1.5.2 - 14.1.5.6; 15.1.8 - 15.1.10; 16.1.3.3
f5
CVE-2023-43124MEDIUMCVSS 5.32023-09-27
CVE-2023-43124 [MEDIUM] CWE-319 CVE-2023-43124: BIG-IP APM clients may send IP traffic outside of the VPN tunnel
CVE-2023-43124: BIG-IP APM clients may send IP traffic outside of the VPN tunnel
BIG-IP APM clients may send IP traffic outside of the VPN tunnel. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Affected Products: BIG-IP APM, Big-Ip Access Policy Manager Client
Affected Versions: 13.1.5.1; 14.1.5.2 - 14.1.5.6; 15.1.8 - 15.1.10; 16.1.3.3
f5
CVE-2023-36858HIGHCVSS 7.12023-08-02
CVE-2023-36858 [HIGH] CWE-345 CVE-2023-36858: An insufficient verification of data vulnerability exists in BIG-IP Edge Client for Windows and macOS that may allow ...
CVE-2023-36858: An insufficient verification of data vulnerability exists in BIG-IP Edge Client for Windows and macOS that may allow ...
An insufficient verification of data vulnerability exists in BIG-IP Edge Client for Windows and macOS that may allow an attacker to modify its configured server list. Note: Software versions whi
f5
CVE-2023-38138HIGHCVSS 7.52023-08-02
CVE-2023-38138 [HIGH] CWE-79 CVE-2023-38138: A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utilit...
CVE-2023-38138: A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utilit...
A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which allows an attacker to run JavaScript in the context of the currently l
f5
CVE-2023-38418HIGHCVSS 7.82023-08-02
CVE-2023-38418 [HIGH] CWE-347 CVE-2023-38418: The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installa...
CVE-2023-38418: The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installa...
The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installation process. Note: Software versions which have reached End of Technical Sup
f5
CVE-2023-3470MEDIUMCVSS 6.02023-08-02
CVE-2023-3470 [MEDIUM] CWE-1391 CVE-2023-3470: Specific F5 BIG-IP platforms with Cavium Nitrox FIPS HSM cards generate a deterministic password for the Crypto User ...
CVE-2023-3470: Specific F5 BIG-IP platforms with Cavium Nitrox FIPS HSM cards generate a deterministic password for the Crypto User ...
Specific F5 BIG-IP platforms with Cavium Nitrox FIPS HSM cards generate a deterministic password for the Crypto User account. The predictable nature of the password allows an authenticated user
f5
CVE-2023-38423MEDIUMCVSS 5.42023-08-02
CVE-2023-38423 [MEDIUM] CWE-79 CVE-2023-38423: A cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that all...
CVE-2023-38423: A cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that all...
A cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in
f5
CVE-2023-38419MEDIUMCVSS 4.32023-08-02
CVE-2023-38419 [MEDIUM] CWE-755 CVE-2023-38419: An authenticated attacker with guest privileges or higher can cause the iControl SOAP process to terminate by sending...
CVE-2023-38419: An authenticated attacker with guest privileges or higher can cause the iControl SOAP process to terminate by sending...
An authenticated attacker with guest privileges or higher can cause the iControl SOAP process to terminate by sending undisclosed requests. Note: Software versions which have reached End of Tec
f5
CVE-2023-24461HIGHCVSS 7.42023-05-03
CVE-2023-24461 [HIGH] CWE-295 CVE-2023-24461: An improper certificate validation vulnerability exists in the BIG-IP Edge Client for Windows and macOS and may allow...
CVE-2023-24461: An improper certificate validation vulnerability exists in the BIG-IP Edge Client for Windows and macOS and may allow...
An improper certificate validation vulnerability exists in the BIG-IP Edge Client for Windows and macOS and may allow an attacker to impersonate a BIG-IP APM system. Note: Software versions whic
f5
CVE-2023-29163HIGHCVSS 7.52023-05-03
CVE-2023-29163 [HIGH] CWE-401 CVE-2023-29163: When UDP profile with idle timeout set to immediate or the value 0 is configured on a virtual server, undisclosed tra...
CVE-2023-29163: When UDP profile with idle timeout set to immediate or the value 0 is configured on a virtual server, undisclosed tra...
When UDP profile with idle timeout set to immediate or the value 0 is configured on a virtual server, undisclosed traffic can cause TMM to terminate. Note: Software versions which have reached E
f5
CVE-2023-27378HIGHCVSS 7.52023-05-03
CVE-2023-27378 [HIGH] CWE-79 CVE-2023-27378: Multiple reflected cross-site scripting (XSS) vulnerabilities exist in undisclosed pages of the BIG-IP Configuration ...
CVE-2023-27378: Multiple reflected cross-site scripting (XSS) vulnerabilities exist in undisclosed pages of the BIG-IP Configuration ...
Multiple reflected cross-site scripting (XSS) vulnerabilities exist in undisclosed pages of the BIG-IP Configuration utility which allow an attacker to run JavaScript in the context of the curren
f5
CVE-2023-24594MEDIUMCVSS 5.32023-05-03
CVE-2023-24594 [MEDIUM] CWE-400 CVE-2023-24594: When an SSL profile is configured on a Virtual Server, undisclosed traffic can cause an increase in CPU or SSL accele...
CVE-2023-24594: When an SSL profile is configured on a Virtual Server, undisclosed traffic can cause an increase in CPU or SSL accele...
When an SSL profile is configured on a Virtual Server, undisclosed traffic can cause an increase in CPU or SSL accelerator resource utilization.
Note: Software versions which have reached End
f5
CVE-2023-22372MEDIUMCVSS 5.92023-05-03
CVE-2023-22372 [MEDIUM] CWE-924 CVE-2023-22372: In the pre connection stage, an improper enforcement of message integrity vulnerability exists in BIG-IP Edge Client ...
CVE-2023-22372: In the pre connection stage, an improper enforcement of message integrity vulnerability exists in BIG-IP Edge Client ...
In the pre connection stage, an improper enforcement of message integrity vulnerability exists in BIG-IP Edge Client for Windows and Mac OS. Note: Software versions which have reached End of T
f5
CVE-2023-28406MEDIUMCVSS 4.32023-05-03
CVE-2023-28406 [MEDIUM] CWE-22 CVE-2023-28406: A directory traversal vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which may allow...
CVE-2023-28406: A directory traversal vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which may allow...
A directory traversal vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which may allow an authenticated attacker to read files with .xml extension. Access to restr
f5
CVE-2023-22374HIGHCVSS 8.52023-02-01
CVE-2023-22374 [HIGH] CWE-134 CVE-2023-22374: A format string vulnerability exists in iControl SOAP that allows an authenticated attacker to crash the iControl SOA...
CVE-2023-22374: A format string vulnerability exists in iControl SOAP that allows an authenticated attacker to crash the iControl SOA...
A format string vulnerability exists in iControl SOAP that allows an authenticated attacker to crash the iControl SOAP CGI process or, potentially execute arbitrary code. In appliance mode BIG-I
f5
CVE-2023-23555HIGHCVSS 7.52023-02-01
CVE-2023-23555 [HIGH] CWE-665 CVE-2023-23555: On BIG-IP Virtual Edition versions 15
CVE-2023-23555: On BIG-IP Virtual Edition versions 15
On BIG-IP Virtual Edition versions 15.1x beginning in 15.1.4 to before 15.1.8 and 14.1.x beginning in 14.1.5 to before 14.1.5.3, and BIG-IP SPK beginning in 1.5.0 to before 1.6.0, when FastL4 profile is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reache
f5
CVE-2023-22340HIGHCVSS 7.52023-02-01
CVE-2023-22340 [HIGH] CWE-476 CVE-2023-22340: On BIG-IP versions 16
CVE-2023-22340: On BIG-IP versions 16
On BIG-IP versions 16.1.x before 16.1.3.3, 15.1.x before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a SIP profile is configured on a Message Routing type virtual server, undisclosed traffic can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Products: BIG-IP AAM, BIG-IP AFM, BIG-IP APM, BI
f5