F5 Big-Ip Application Security Manager vulnerabilities
540 known vulnerabilities affecting f5/big-ip_application_security_manager.
Total CVEs
540
CISA KEV
11
actively exploited
Public exploits
23
Exploited in wild
11
Severity breakdown
CRITICAL43HIGH310MEDIUM180LOW7
Vulnerabilities
Page 17 of 27
CVE-2019-6669HIGHCVSS 7.5≥ 11.5.1, ≤ 11.6.5.1≥ 12.1.0, ≤ 12.1.5+4 more2019-11-27
CVE-2019-6669 [HIGH] CVE-2019-6669: On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.1-11
On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.1-11.6.5.1, undisclosed traffic flow may cause TMM to restart under some circumstances.
nvd
CVE-2019-6670MEDIUMCVSS 4.4≥ 11.5.1, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.5+4 more2019-11-27
CVE-2019-6670 [MEDIUM] CWE-312 CVE-2019-6670: On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.1-11
On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.1-11.6.5, vCMP hypervisors are incorrectly exposing the plaintext unit key for their vCMP guests on the filesystem.
nvd
CVE-2019-6675CRITICALCVSS 9.8≥ 15.0.1.0.33.11-eng_hotfix, ≤ 15.0.1.0.48.11-eng_hotfixv14.1.0.3.0.79.6-eng_hotfix+22 more2019-11-26
CVE-2019-6675 [CRITICAL] CWE-287 CVE-2019-6675: BIG-IP configurations using Active Directory, LDAP, or Client Certificate LDAP for management authen
BIG-IP configurations using Active Directory, LDAP, or Client Certificate LDAP for management authentication with multiple servers are exposed to a vulnerability which allows an authentication bypass. This can result in a complete compromise of the system. This issue only impacts specific engineering hotfixes using the aforementioned authentication
nvd
CVE-2019-6660HIGHCVSS 7.5≥ 13.1.0, < 13.1.3≥ 14.0.0, < 14.0.1.1+1 more2019-11-15
CVE-2019-6660 [HIGH] CWE-400 CVE-2019-6660: On BIG-IP 14.1.0-14.1.2, 14.0.0-14.0.1, and 13.1.0-13.1.1, undisclosed HTTP requests may consume exc
On BIG-IP 14.1.0-14.1.2, 14.0.0-14.0.1, and 13.1.0-13.1.1, undisclosed HTTP requests may consume excessive amounts of systems resources which may lead to a denial of service.
nvd
CVE-2019-6659HIGHCVSS 7.5≥ 14.0.0, < 14.1.0.22019-11-15
CVE-2019-6659 [HIGH] CVE-2019-6659: On version 14.0.0-14.1.0.1, BIG-IP virtual servers with TLSv1.3 enabled may experience a denial of s
On version 14.0.0-14.1.0.1, BIG-IP virtual servers with TLSv1.3 enabled may experience a denial of service due to undisclosed incoming messages.
nvd
CVE-2019-6664HIGHCVSS 7.5≥ 14.1.0, < 14.1.2v15.0.02019-11-15
CVE-2019-6664 [HIGH] CVE-2019-6664: On BIG-IP 15.0.0 and 14.1.0-14.1.0.6, under certain conditions, network protections on the managemen
On BIG-IP 15.0.0 and 14.1.0-14.1.0.6, under certain conditions, network protections on the management port do not follow current best practices.
nvd
CVE-2019-6663MEDIUMCVSS 5.5≥ 11.5.2, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.5+3 more2019-11-15
CVE-2019-6663 [MEDIUM] CWE-20 CVE-2019-6663: The BIG-IP 15.0.0-15.0.1, 14.0.0-14.1.2.2, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.1-11.6.5.1, BIG-
The BIG-IP 15.0.0-15.0.1, 14.0.0-14.1.2.2, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.1-11.6.5.1, BIG-IQ 7.0.0, 6.0.0-6.1.0, and 5.2.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1 configuration utility is vulnerable to Anti DNS Pinning (DNS Rebinding) attack.
nvd
CVE-2019-6662MEDIUMCVSS 6.5≥ 13.1.0, < 13.1.1.52019-11-15
CVE-2019-6662 [MEDIUM] CWE-532 CVE-2019-6662: On BIG-IP 13.1.0-13.1.1.4, sensitive information is logged into the local log files and/or remote lo
On BIG-IP 13.1.0-13.1.1.4, sensitive information is logged into the local log files and/or remote logging targets when restjavad processes an invalid request. Users with access to the log files would be able to view that data.
nvd
CVE-2018-12207MEDIUMCVSS 6.5≥ 11.5.2, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.5+3 more2019-11-14
CVE-2018-12207 [MEDIUM] CWE-20 CVE-2018-12207: Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(
Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local access.
nvd
CVE-2019-6657MEDIUMCVSS 6.1≥ 11.5.2, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.5+1 more2019-11-01
CVE-2019-6657 [MEDIUM] CWE-79 CVE-2019-6657: On BIG-IP 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, a reflected cross-site scripting (XSS
On BIG-IP 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, a reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Traffic Management User Interface (TMUI), also known as the BIG-IP Configuration utility.
nvd
CVE-2018-5743HIGHCVSS 7.5≥ 11.5.2, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.4+3 more2019-10-09
CVE-2018-5743 [HIGH] CWE-770 CVE-2018-5743: By design, BIND is intended to limit the number of TCP clients that can be connected at any given ti
By design, BIND is intended to limit the number of TCP clients that can be connected at any given time. The number of allowed connections is a tunable parameter which, if unset, defaults to a conservative value for most servers. Unfortunately, the code which was intended to limit the number of simultaneous connections contained an error which could be e
nvd
CVE-2019-6471MEDIUMCVSS 5.9≥ 11.5.2, ≤ 11.5.9≥ 11.6.1, ≤ 11.6.4+5 more2019-10-09
CVE-2019-6471 [MEDIUM] CWE-362 CVE-2019-6471: A race condition which may occur when discarding malformed packets can result in BIND exiting due to
A race condition which may occur when discarding malformed packets can result in BIND exiting due to a REQUIRE assertion failure in dispatch.c. Versions affected: BIND 9.11.0 -> 9.11.7, 9.12.0 -> 9.12.4-P1, 9.14.0 -> 9.14.2. Also all releases of the BIND 9.13 development branch and version 9.15.0 of the BIND 9.15 development branch and BIND Supported
nvd
CVE-2018-14880HIGHCVSS 7.5≥ 11.5.2, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.5+3 more2019-10-03
CVE-2018-14880 [HIGH] CWE-125 CVE-2018-14880: The OSPFv3 parser in tcpdump before 4.9.3 has a buffer over-read in print-ospf6.c:ospf6_print_lshdr(
The OSPFv3 parser in tcpdump before 4.9.3 has a buffer over-read in print-ospf6.c:ospf6_print_lshdr().
nvd
CVE-2018-14468HIGHCVSS 7.5≥ 11.6.0, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.5+3 more2019-10-03
CVE-2018-14468 [HIGH] CWE-125 CVE-2018-14468: The FRF.16 parser in tcpdump before 4.9.3 has a buffer over-read in print-fr.c:mfr_print().
The FRF.16 parser in tcpdump before 4.9.3 has a buffer over-read in print-fr.c:mfr_print().
nvd
CVE-2019-6651MEDIUMCVSS 5.3≥ 11.5.1, ≤ 11.6.4≥ 12.1.0, ≤ 12.1.4.1+4 more2019-09-25
CVE-2019-6651 [MEDIUM] CWE-203 CVE-2019-6651: In BIG-IP 15.0.0, 14.1.0-14.1.0.6, 14.0.0-14.0.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, 11.5.1-11.6.4,
In BIG-IP 15.0.0, 14.1.0-14.1.0.6, 14.0.0-14.0.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, 11.5.1-11.6.4, BIG-IQ 7.0.0, 6.0.0-6.1.0,5.2.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1, the Configuration utility login page may not follow best security practices when handling a malicious request.
nvd
CVE-2019-6654MEDIUMCVSS 4.3≥ 11.5.1, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.5+2 more2019-09-25
CVE-2019-6654 [MEDIUM] CWE-20 CVE-2019-6654: On versions 14.0.0-14.1.2, 13.0.0-13.1.3, 12.1.0-12.1.5, and 11.5.1-11.6.5, the BIG-IP system fails
On versions 14.0.0-14.1.2, 13.0.0-13.1.3, 12.1.0-12.1.5, and 11.5.1-11.6.5, the BIG-IP system fails to perform Martian Address Filtering (As defined in RFC 1812 section 5.3.7) on the control plane (management interface). This may allow attackers on an adjacent system to force BIG-IP into processing packets with spoofed source addresses.
nvd
CVE-2019-6655MEDIUMCVSS 5.3≥ 11.5.2, ≤ 11.5.9≥ 11.6.1, ≤ 11.6.4+2 more2019-09-25
CVE-2019-6655 [MEDIUM] CVE-2019-6655: On versions 13.0.0-13.1.0.1, 12.1.0-12.1.4.1, 11.6.1-11.6.4, and 11.5.1-11.5.9, BIG-IP platforms whe
On versions 13.0.0-13.1.0.1, 12.1.0-12.1.4.1, 11.6.1-11.6.4, and 11.5.1-11.5.9, BIG-IP platforms where AVR, ASM, APM, PEM, AFM, and/or AAM is provisioned may leak sensitive data.
nvd
CVE-2019-6649CRITICALCVSS 9.1≥ 11.5.2, ≤ 11.5.9≥ 11.6.1, ≤ 11.6.4+5 more2019-09-20
CVE-2019-6649 [CRITICAL] CVE-2019-6649: F5 BIG-IP 15.0.0, 14.1.0-14.1.0.6, 14.0.0-14.0.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, 11.6.0-11.6.4,
F5 BIG-IP 15.0.0, 14.1.0-14.1.0.6, 14.0.0-14.0.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, 11.6.0-11.6.4, and 11.5.1-11.5.9 and Enterprise Manager 3.1.1 may expose sensitive information and allow the system configuration to be modified when using non-default ConfigSync settings.
nvd
CVE-2019-6650CRITICALCVSS 9.1≥ 11.5.2, ≤ 11.5.9≥ 11.6.1, ≤ 11.6.4+5 more2019-09-20
CVE-2019-6650 [CRITICAL] CVE-2019-6650: F5 BIG-IP ASM 15.0.0, 14.1.0-14.1.0.6, 14.0.0-14.0.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, 11.6.0-11.
F5 BIG-IP ASM 15.0.0, 14.1.0-14.1.0.6, 14.0.0-14.0.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, 11.6.0-11.6.4, and 11.5.1-11.5.9 may expose sensitive information and allow the system configuration to be modified when using non-default settings.
nvd
CVE-2019-6644CRITICALCVSS 9.4≥ 12.1.3, ≤ 12.1.4≥ 13.0.0, ≤ 13.1.2+2 more2019-09-04
CVE-2019-6644 [CRITICAL] CVE-2019-6644: Similar to the issue identified in CVE-2018-12120, on versions 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.
Similar to the issue identified in CVE-2018-12120, on versions 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.2, and 12.1.0-12.1.4 BIG-IP will bind a debug nodejs process to all interfaces when invoked. This may expose the process to unauthorized users if the plugin is left in debug mode and the port is accessible.
nvd