cbcvebase.

F5 Big-Ip Application Acceleration Manager vulnerabilities

518 known vulnerabilities affecting f5/big-ip_application_acceleration_manager.

Total CVEs
518
CISA KEV
11
actively exploited
Public exploits
19
Exploited in wild
15
Severity breakdown
CRITICAL37HIGH290MEDIUM187LOW4

Vulnerabilities

Page 16 of 26
CVE-2018-15318P3HIGHCVSS 7.5≥ 12.1.3.4, ≤ 12.1.3.6≥ 13.0.0, ≤ 13.1.1.1+1 more2018-10-31
CVE-2018-15318 [HIGH] CWE-20 CVE-2018-15318: In BIG-IP 14.0.0-14.0.0.2, 13.1.0.4-13.1.1.1, or 12.1.3.4-12.1.3.6, If an MPTCP connection receives In BIG-IP 14.0.0-14.0.0.2, 13.1.0.4-13.1.1.1, or 12.1.3.4-12.1.3.6, If an MPTCP connection receives an abort signal while the initial flow is not the primary flow, the initial flow will remain after the closing procedure is complete. TMM may restart and produce a core file as a result of this condition.
nvd
CVE-2016-9253P3HIGHCVSS 7.5v12.1.0v12.1.1+1 more2017-05-09
CVE-2016-9253 [HIGH] CWE-20 CVE-2016-9253: In F5 BIG-IP 12.1.0 through 12.1.2, specific websocket traffic patterns may cause a disruption of se In F5 BIG-IP 12.1.0 through 12.1.2, specific websocket traffic patterns may cause a disruption of service for virtual servers configured to use the websocket profile.
nvd
CVE-2018-15320P3HIGHCVSS 7.5≥ 13.0.0, ≤ 13.1.1.1≥ 14.0.0, ≤ 14.0.0.22018-10-31
CVE-2018-15320 [HIGH] CVE-2018-15320: On BIG-IP 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1, undisclosed traffic patterns may lead to denial of ser On BIG-IP 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1, undisclosed traffic patterns may lead to denial of service conditions for the BIG-IP system. The configuration which exposes this condition is the BIG-IP self IP address which is part of a VLAN group and has the Port Lockdown setting configured with anything other than "allow-all".
nvd
CVE-2020-5872P3HIGHCVSS 7.5≥ 12.1.0, ≤ 12.1.4.1≥ 13.1.0, ≤ 13.1.3.1+2 more2020-04-30
CVE-2020-5872 [HIGH] CVE-2020-5872: On BIG-IP 14.1.0-14.1.2.3, 14.0.0-14.0.1, 13.1.0-13.1.3.1, and 12.1.0-12.1.4.1, when processing TLS On BIG-IP 14.1.0-14.1.2.3, 14.0.0-14.0.1, 13.1.0-13.1.3.1, and 12.1.0-12.1.4.1, when processing TLS traffic with hardware cryptographic acceleration enabled on platforms with Intel QAT hardware, the Traffic Management Microkernel (TMM) may stop responding and cause a failover event.
nvd
CVE-2020-5883P3HIGHCVSS 7.5≥ 13.1.0, ≤ 13.1.3.1≥ 14.0.0, ≤ 14.0.1+2 more2020-04-30
CVE-2020-5883 [HIGH] CWE-401 CVE-2020-5883: On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2.3, 14.0.0-14.0.1, and 13.1.0-13.1.3.1, when a virtual server On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2.3, 14.0.0-14.0.1, and 13.1.0-13.1.3.1, when a virtual server is configured with HTTP explicit proxy and has an attached HTTP_PROXY_REQUEST iRule, POST requests sent to the virtual server cause an xdata memory leak.
nvd
CVE-2020-5926P3HIGHCVSS 7.5≥ 14.1.0, < 14.1.2.7≥ 15.0.0, < 15.0.1.4+1 more2020-08-26
CVE-2020-5926 [HIGH] CWE-404 CVE-2020-5926: In BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, and 14.1.0-14.1.2.6, a BIG-IP virtual server wi In BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, and 14.1.0-14.1.2.6, a BIG-IP virtual server with a Session Initiation Protocol (SIP) ALG profile, parsing SIP messages that contain a multi-part MIME payload with certain boundary strings can cause TMM to free memory to the wrong cache.
nvd
CVE-2020-5861P3HIGHCVSS 7.5≥ 12.1.0, ≤ 12.1.52020-03-27
CVE-2020-5861 [HIGH] CWE-119 CVE-2020-5861: On BIG-IP 12.1.0-12.1.5, the TMM process may produce a core file in some cases when Ram Cache incorr On BIG-IP 12.1.0-12.1.5, the TMM process may produce a core file in some cases when Ram Cache incorrectly optimizes stored data resulting in memory errors.
nvd
CVE-2019-6676P3HIGHCVSS 7.5≥ 13.1.0, < 13.1.3.2≥ 14.0.0, < 14.1.2.3+1 more2019-12-23
CVE-2019-6676 [HIGH] CVE-2019-6676: On versions 15.0.0-15.0.1, 14.0.0-14.1.2.2, and 13.1.0-13.1.3.1, TMM may restart on BIG-IP Virtual E On versions 15.0.0-15.0.1, 14.0.0-14.1.2.2, and 13.1.0-13.1.3.1, TMM may restart on BIG-IP Virtual Edition (VE) when using virtio direct descriptors and packets 2 KB or larger.
nvd
CVE-2019-6683P3HIGHCVSS 7.5≥ 11.5.2, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.5+4 more2019-12-23
CVE-2019-6683 [HIGH] CWE-400 CVE-2019-6683: On versions 15.0.0-15.0.1.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11. On versions 15.0.0-15.0.1.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, BIG-IP virtual servers with Loose Initiation enabled on a FastL4 profile may be subject to excessive flow usage under undisclosed conditions.
nvd
CVE-2019-6664P3HIGHCVSS 7.5≥ 14.1.0, < 14.1.2v15.0.02019-11-15
CVE-2019-6664 [HIGH] CVE-2019-6664: On BIG-IP 15.0.0 and 14.1.0-14.1.0.6, under certain conditions, network protections on the managemen On BIG-IP 15.0.0 and 14.1.0-14.1.0.6, under certain conditions, network protections on the management port do not follow current best practices.
nvd
CVE-2017-6145P3HIGHCVSS 7.3v12.1.0v12.1.1+2 more2017-10-20
CVE-2017-6145 [HIGH] CWE-613 CVE-2017-6145: iControl REST in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSaf iControl REST in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe 12.0.0 through 12.1.2 and 13.0.0 includes a service to convert authorization BIGIPAuthCookie cookies to X-F5-Auth-Token tokens. This service does not properly re-validate cookies when making that conversion, allowing once-valid but now expired cookies t
nvd
CVE-2015-7393P3HIGHCVSS 7.4v11.4.0v11.4.1+4 more2016-01-12
CVE-2015-7393 [HIGH] CVE-2015-7393: dcoep in BIG-IP LTM, Analytics, APM, ASM, and Link Controller 11.2.0 through 11.6.0 and 12.0.0 befor dcoep in BIG-IP LTM, Analytics, APM, ASM, and Link Controller 11.2.0 through 11.6.0 and 12.0.0 before 12.0.0 HF1, BIG-IP AAM 11.4.0 through 11.6.0 and 12.0.0 before 12.0.0 HF1, BIG-IP AFM and PEM 11.3.0 through 11.6.0 and 12.0.0 before 12.0.0 HF1, BIG-IP DNS 12.0.0 before 12.0.0 HF1, BIG-IP Edge Gateway, WebAccelerator, and WOM 11.2.0 through 11.3.0, BIG-IP GTM
nvd
CVE-2019-6617P3MEDIUMCVSS 6.5≥ 11.5.2, < 11.5.9≥ 11.6.1, < 11.6.4+3 more2019-05-03
CVE-2019-6617 [MEDIUM] CWE-269 CVE-2019-6617: On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, a use On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, a user with the Resource Administrator role is able to overwrite sensitive low-level files (such as /etc/passwd) using SFTP to modify user permissions, without Advanced Shell access. This is contrary to our definition for the Resource Administrator (RA) role
nvd
CVE-2019-12295P3HIGHCVSS 7.5≥ 12.1.3.6, < 12.1.5.3≥ 13.1.1.2, < 13.1.3.5+4 more2019-05-23
CVE-2019-12295 [HIGH] CWE-674 CVE-2019-12295: In Wireshark 3.0.0 to 3.0.1, 2.6.0 to 2.6.8, and 2.4.0 to 2.4.14, the dissection engine could crash. In Wireshark 3.0.0 to 3.0.1, 2.6.0 to 2.6.8, and 2.4.0 to 2.4.14, the dissection engine could crash. This was addressed in epan/packet.c by restricting the number of layers and consequently limiting recursion.
nvd
CVE-2026-40462P3MEDIUMCVSS 6.5≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+2 more2026-05-13
CVE-2026-40462 [MEDIUM] CWE-732 CVE-2026-40462: Incorrect permission assignment vulnerabilities exist in iControl REST and TMOS shell (tmsh) undiscl Incorrect permission assignment vulnerabilities exist in iControl REST and TMOS shell (tmsh) undisclosed command which may allow an authenticated attacker to view sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2020-5945P3HIGHCVSS 8.4≥ 14.1.0, < 14.1.2.8≥ 15.1.0, < 15.1.1+1 more2020-11-05
CVE-2020-5945 [HIGH] CWE-79 CVE-2020-5945: In BIG-IP versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.2.7, undisclosed TMUI page cont In BIG-IP versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.2.7, undisclosed TMUI page contains a stored cross site scripting vulnerability (XSS). The issue allows a minor privilege escalation for resource admin to escalate to full admin.
nvd
CVE-2013-3587P3MEDIUMCVSS 5.9≥ 11.4.0, ≤ 11.6.1≥ 12.0.0, ≤ 12.1.2+1 more2020-02-21
CVE-2013-3587 [MEDIUM] CVE-2013-3587: The HTTPS protocol, as used in unspecified web applications, can encrypt compressed data without pro The HTTPS protocol, as used in unspecified web applications, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which makes it easier for man-in-the-middle attackers to obtain plaintext secret values by observing length differences during a series of guesses in which a string in an HTTP request URL potentially matches
nvd
CVE-2016-9249P3HIGHCVSS 7.5v12.0.0v12.1.0+1 more2017-01-31
CVE-2016-9249 [HIGH] CWE-20 CVE-2016-9249: An undisclosed traffic pattern received by a BIG-IP Virtual Server with TCP Fast Open enabled may ca An undisclosed traffic pattern received by a BIG-IP Virtual Server with TCP Fast Open enabled may cause the Traffic Management Microkernel (TMM) to restart, resulting in a Denial-of-Service (DoS).
nvd
CVE-2016-9252P3HIGHCVSS 7.5v11.4.0v11.4.1+10 more2017-03-27
CVE-2016-9252 [HIGH] CWE-19 CVE-2016-9252: The Traffic Management Microkernel (TMM) in F5 BIG-IP before 11.5.4 HF3, 11.6.x before 11.6.1 HF2 an The Traffic Management Microkernel (TMM) in F5 BIG-IP before 11.5.4 HF3, 11.6.x before 11.6.1 HF2 and 12.x before 12.1.2 does not properly handle minimum path MTU options for IPv6, which allows remote attackers to cause a denial-of-service (DoS) through unspecified vectors.
nvd
CVE-2025-24320P3HIGHCVSS 8.0≥ 15.1.0, < 15.1.10.6≥ 16.1.0, < 16.1.5.2+1 more2025-02-05
CVE-2025-24320 [HIGH] CVE-2025-24320: A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Config A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. This vulnerability is due to an incomplete fix for CVE-2024-31156 https://my.f5.com/manage/s/article/K000138636 . Note: Software versions which have reach
nvd
F5 Big-Ip Application Acceleration Manager vulnerabilities | cvebase