F5 Big-Ip Application Security Manager vulnerabilities
575 known vulnerabilities affecting f5/big-ip_application_security_manager.
Total CVEs
575
CISA KEV
11
actively exploited
Public exploits
23
Exploited in wild
15
Severity breakdown
CRITICAL44HIGH327MEDIUM198LOW6
Vulnerabilities
Page 14 of 29
CVE-2022-35240P3HIGHCVSS 7.5≥ 14.1.0, < 14.1.5≥ 15.1.0, < 15.1.6.1+1 more2022-08-04
CVE-2022-35240 [HIGH] CWE-404 CVE-2022-35240: In BIG-IP Versions 16.1.x before 16.1.2.2, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when th
In BIG-IP Versions 16.1.x before 16.1.2.2, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when the Message Routing (MR) Message Queuing Telemetry Transport (MQTT) profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (
nvd
CVE-2022-35236P3HIGHCVSS 7.5≥ 14.1.0, < 14.1.5≥ 15.1.0, < 15.1.6.1+1 more2022-08-04
CVE-2022-35236 [HIGH] CWE-400 CVE-2022-35236: In BIG-IP Versions 16.1.x before 16.1.2.2, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when an
In BIG-IP Versions 16.1.x before 16.1.2.2, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when an HTTP2 profile is configured on a virtual server, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-23555P3HIGHCVSS 7.5≥ 14.1.5, < 14.1.5.3≥ 15.1.4, < 15.1.82023-02-01
CVE-2023-23555 [HIGH] CWE-665 CVE-2023-23555: On BIG-IP Virtual Edition versions 15.1x beginning in 15.1.4 to before 15.1.8 and 14.1.x beginning i
On BIG-IP Virtual Edition versions 15.1x beginning in 15.1.4 to before 15.1.8 and 14.1.x beginning in 14.1.5 to before 14.1.5.3, and BIG-IP SPK beginning in 1.5.0 to before 1.6.0, when FastL4 profile is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which hav
nvd
CVE-2023-22664P3HIGHCVSS 7.5≥ 16.1.0, < 16.1.3.3≥ 17.0.0, < 17.0.0.22023-02-01
CVE-2023-22664 [HIGH] CWE-400 CVE-2023-22664: On BIG-IP versions 17.0.x before 17.0.0.2 and 16.1.x before 16.1.3.3, and BIG-IP SPK starting in ver
On BIG-IP versions 17.0.x before 17.0.0.2 and 16.1.x before 16.1.3.3, and BIG-IP SPK starting in version 1.6.0, when a client-side HTTP/2 profile and the HTTP MRF Router option are enabled for a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support
nvd
CVE-2022-36795P3HIGHCVSS 7.5≥ 14.1.0, < 14.1.5.1≥ 15.1.0, < 15.1.7+2 more2022-10-19
CVE-2022-36795 [HIGH] CWE-682 CVE-2022-36795: In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.7, and 14.1.x
In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.7, and 14.1.x before 14.1.5.1, when an LTM TCP profile with Auto Receive Window Enabled is configured on a virtual server, undisclosed traffic can cause the virtual server to stop processing new client connections.
nvd
CVE-2016-2084P3HIGHCVSS 7.4v11.3.0v11.4.0+8 more2016-04-13
CVE-2016-2084 [HIGH] CWE-200 CVE-2016-2084: F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.x, 11.4.x before 11.4.1 build
F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.x, 11.4.x before 11.4.1 build 685-HF10, 11.5.1 before build 10.104.180, 11.5.2 before 11.5.4 build 0.1.256, 11.6.0 before build 6.204.442, and 12.0.0 before build 1.14.628; BIG-IP AAM 11.4.x before 11.4.1 build 685-HF10, 11.5.1 before build 10.104.180, 11.5.2 before 11.5.4 build 0.1.
nvd
CVE-2024-23805P3HIGHCVSS 7.5≥ 15.1.0, < 15.1.10≥ 16.1.0, < 16.1.4+1 more2024-02-14
CVE-2024-23805 [HIGH] CWE-131 CVE-2024-23805: Undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. For the Appli
Undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. For the Application Visibility and Reporting module, this may occur when the HTTP Analytics profile with URLs enabled under Collected Entities is configured on a virtual server and the DB variables avr.IncludeServerInURI or avr.CollectOnlyHostnameFromURI are enabled.
nvd
CVE-2023-41085P3HIGHCVSS 7.5≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, ≤ 14.1.5+2 more2023-10-10
CVE-2023-41085 [HIGH] CWE-755 CVE-2023-41085: When IPSec is configured on a Virtual Server, undisclosed traffic can cause TMM to terminate. Not
When IPSec is configured on a Virtual Server, undisclosed traffic can cause TMM to terminate.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2025-20058P3HIGHCVSS 7.5≥ 15.1.0, ≤ 15.1.10≥ 16.1.0, < 16.1.6+1 more2025-02-05
CVE-2025-20058 [HIGH] CWE-400 CVE-2025-20058: When a BIG-IP message routing profile is configured on a virtual server, undisclosed traffic can cau
When a BIG-IP message routing profile is configured on a virtual server, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
CVE-2025-24326P3HIGHCVSS 7.5≥ 15.1.0, < 15.1.10.6.0.11.6-ENG≥ 16.1.0, < 16.1.5+1 more2025-02-05
CVE-2025-24326 [HIGH] CWE-787 CVE-2025-24326: When BIG-IP Advanced WAF/ASM Behavioral DoS (BADoS) TLS Signatures feature is configured, undisclose
When BIG-IP Advanced WAF/ASM Behavioral DoS (BADoS) TLS Signatures feature is configured, undisclosed traffic can case an increase in memory resource utilization.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2025-22846P3HIGHCVSS 7.5≥ 15.1.0, < 15.1.10.6.0.11.6≥ 16.1.0, < 16.1.5+1 more2025-02-05
CVE-2025-22846 [HIGH] CWE-404 CVE-2025-22846: When SIP Session and Router ALG profiles are configured on a Message Routing type virtual server, un
When SIP Session and Router ALG profiles are configured on a Message Routing type virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2016-7472P3HIGHCVSS 7.5v12.1.0v12.1.12018-04-03
CVE-2016-7472 [HIGH] CWE-20 CVE-2016-7472: F5 BIG-IP ASM version 12.1.0 - 12.1.1 may allow remote attackers to cause a denial of service (DoS)
F5 BIG-IP ASM version 12.1.0 - 12.1.1 may allow remote attackers to cause a denial of service (DoS) via a crafted HTTP request.
nvd
CVE-2025-59483P3MEDIUMCVSS 6.5≥ 15.1.0, < 15.1.10.8≥ 16.1.0, < 16.1.6.1+2 more2025-10-15
CVE-2025-59483 [MEDIUM] CWE-73 CVE-2025-59483: A validation vulnerability exists in an undisclosed URL in the Configuration utility. Note: Softwar
A validation vulnerability exists in an undisclosed URL in the Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-40699P3MEDIUMCVSS 6.5≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+1 more2026-05-13
CVE-2026-40699 [MEDIUM] CWE-643 CVE-2026-40699: A vulnerability exists in the undisclosed pages in the Configuration utility that may allow a low-pr
A vulnerability exists in the undisclosed pages in the Configuration utility that may allow a low-privileged authenticated attacker to access to undisclosed sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2016-5023P3HIGHCVSS 7.5v11.2.1v11.4.1+4 more2016-08-26
CVE-2016-5023 [HIGH] CWE-284 CVE-2016-5023: Virtual servers in F5 BIG-IP systems 11.2.1 HF11 through HF15, 11.4.1 HF4 through HF10, 11.5.3 throu
Virtual servers in F5 BIG-IP systems 11.2.1 HF11 through HF15, 11.4.1 HF4 through HF10, 11.5.3 through 11.5.4, 11.6.0 HF5 through HF7, and 12.0.0, when configured with a TCP profile, allow remote attackers to cause a denial of service (Traffic Management Microkernel restart) via crafted network traffic.
nvd
CVE-2017-6132P3HIGHCVSS 7.5≥ 11.6.0, ≤ 11.6.1≥ 12.0.0, ≤ 12.1.2+6 more2017-12-21
CVE-2017-6132 [HIGH] CWE-20 CVE-2017-6132: In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and Websafe software
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and Websafe software version 13.0.0, 12.0.0 to 12.1.2, 11.6.0 to 11.6.1 and 11.5.0 - 11.5.4, an undisclosed sequence of packets sent to BIG-IP High Availability state mirror listeners (primary and/or secondary IP) may cause TMM to restart.
nvd
CVE-2019-6631P3HIGHCVSS 7.5≥ 11.5.2, ≤ 11.6.42019-07-03
CVE-2019-6631 [HIGH] CVE-2019-6631: On BIG-IP 11.5.1-11.6.4, iRules performing HTTP header manipulation may cause an interruption to ser
On BIG-IP 11.5.1-11.6.4, iRules performing HTTP header manipulation may cause an interruption to service when processing traffic handled by a Virtual Server with an associated HTTP profile, in specific circumstances, when the requests do not strictly conform to RFCs.
nvd
CVE-2016-7476P3HIGHCVSS 7.5v11.3.0v11.4.0+6 more2017-05-11
CVE-2016-7476 [HIGH] CWE-20 CVE-2016-7476: The Traffic Management Microkernel (TMM) in F5 BIG-IP LTM, AAM, AFM, APM, ASM, GTM, Link Controller,
The Traffic Management Microkernel (TMM) in F5 BIG-IP LTM, AAM, AFM, APM, ASM, GTM, Link Controller, PEM, PSM, and WebSafe 11.6.0 before 11.6.0 HF6, 11.5.0 before 11.5.3 HF2, and 11.3.0 before 11.4.1 HF10 may suffer from a memory leak while handling certain types of TCP traffic. Remote attackers may cause a denial of service (DoS) by way of a crafted TCP
nvd
CVE-2018-5534P3HIGHCVSS 7.5≥ 11.5.0, ≤ 11.5.6≥ 11.6.0, ≤ 11.6.3.1+3 more2018-07-19
CVE-2018-5534 [HIGH] CWE-20 CVE-2018-5534: Under certain conditions on F5 BIG-IP 13.1.0-13.1.0.5, 13.0.0, 12.1.0-12.1.3.1, 11.6.0-11.6.3.1, or
Under certain conditions on F5 BIG-IP 13.1.0-13.1.0.5, 13.0.0, 12.1.0-12.1.3.1, 11.6.0-11.6.3.1, or 11.5.0-11.5.6, TMM may core while processing SSL forward proxy traffic.
nvd
CVE-2018-5517P3HIGHCVSS 7.5≥ 13.1.0, ≤ 13.1.0.52018-05-02
CVE-2018-5517 [HIGH] CWE-20 CVE-2018-5517: On F5 BIG-IP 13.1.0-13.1.0.5, malformed TCP packets sent to a self IP address or a FastL4 virtual se
On F5 BIG-IP 13.1.0-13.1.0.5, malformed TCP packets sent to a self IP address or a FastL4 virtual server may cause an interruption of service. The control plane is not exposed to this issue. This issue impacts the data plane virtual servers and self IPs.
nvd