F5 Big-Ip Application Security Manager vulnerabilities
575 known vulnerabilities affecting f5/big-ip_application_security_manager.
Total CVEs
575
CISA KEV
11
actively exploited
Public exploits
23
Exploited in wild
15
Severity breakdown
CRITICAL44HIGH327MEDIUM198LOW6
Vulnerabilities
Page 22 of 29
CVE-2017-6159P4MEDIUMCVSS 5.9v11.6.0v11.6.1+4 more2017-10-27
CVE-2017-6159 [MEDIUM] CVE-2017-6159: F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM, Websafe software versi
F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM, Websafe software version 12.0.0 to 12.1.2, 11.6.0 to 11.6.1 are vulnerable to a denial of service attack when the MPTCP option is enabled on a virtual server. Data plane is vulnerable when using the MPTCP option of a TCP profile. There is no control plane exposure. An attacker may b
nvd
CVE-2018-15311P4MEDIUMCVSS 5.9≥ 11.5.1, ≤ 11.5.6≥ 11.6.0.0, ≤ 11.6.3.2+2 more2018-10-10
CVE-2018-15311 [MEDIUM] CVE-2018-15311: When F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.5, 11.6.0-11.6.3.2, or 11.5.1-11.5.6 is processing spe
When F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.5, 11.6.0-11.6.3.2, or 11.5.1-11.5.6 is processing specially crafted TCP traffic with the Large Receive Offload (LRO) feature enabled, TMM may crash, leading to a failover event. This vulnerability is not exposed unless LRO is enabled, so most affected customers will be on 13.1.x. LRO has been available since 11
nvd
CVE-2021-22984P4MEDIUMCVSS 6.1≥ 11.6.1, < 11.6.5.2≥ 12.1.0, < 12.1.5.2+4 more2021-02-12
CVE-2021-22984 [MEDIUM] CWE-601 CVE-2021-22984: On BIG-IP Advanced WAF and ASM version 15.1.x before 15.1.0.2, 15.0.x before 15.0.1.4, 14.1.x before
On BIG-IP Advanced WAF and ASM version 15.1.x before 15.1.0.2, 15.0.x before 15.0.1.4, 14.1.x before 14.1.2.5, 13.1.x before 13.1.3.4, 12.1.x before 12.1.5.2, and 11.6.x before 11.6.5.2, when receiving a unauthenticated client request with a maliciously crafted URI, a BIG-IP Advanced WAF or ASM virtual server configured with a DoS profile with Proac
nvd
CVE-2023-3470P4MEDIUMCVSS 6.1≥ 13.1.0, < 13.1.4≥ 14.1.0, < 14.1.4+1 more2023-08-02
CVE-2023-3470 [MEDIUM] CWE-1391 CVE-2023-3470: Specific F5 BIG-IP platforms with Cavium Nitrox FIPS HSM cards generate a deterministic password fo
Specific F5 BIG-IP platforms with Cavium Nitrox FIPS HSM cards generate a deterministic password for the Crypto User account. The predictable nature of the password allows an authenticated user with TMSH access to the BIG-IP system, or anyone with physical access to the FIPS HSM, the information required to generate the correct password. On vCMP syste
nvd
CVE-2019-6593P4MEDIUMCVSS 5.9≥ 11.5.1, ≤ 11.5.4v11.6.1+1 more2019-02-26
CVE-2019-6593 [MEDIUM] CWE-327 CVE-2019-6593: On BIG-IP 11.5.1-11.5.4, 11.6.1, and 12.1.0, a virtual server configured with a Client SSL profile m
On BIG-IP 11.5.1-11.5.4, 11.6.1, and 12.1.0, a virtual server configured with a Client SSL profile may be vulnerable to a chosen ciphertext attack against CBC ciphers. When exploited, this may result in plaintext recovery of encrypted messages through a man-in-the-middle (MITM) attack, despite the attacker not having gained access to the server's priv
nvd
CVE-2023-22302P4MEDIUMCVSS 5.9≥ 16.1.2.2, < 16.1.3.3≥ 17.0.0, < 17.0.0.22023-02-01
CVE-2023-22302 [MEDIUM] CWE-772 CVE-2023-22302: In BIG-IP versions 17.0.x before 17.0.0.2, and 16.1.x beginning in 16.1.2.2 to before 16.1.3.3, when
In BIG-IP versions 17.0.x before 17.0.0.2, and 16.1.x beginning in 16.1.2.2 to before 16.1.3.3, when an HTTP profile is configured on a virtual server and conditions beyond the attacker’s control exist on the target pool member, undisclosed requests sent to the BIG-IP system can cause the Traffic Management Microkernel (TMM) to terminate. Note: Soft
nvd
CVE-2025-58153P4MEDIUMCVSS 5.9≥ 15.1.0, < 15.1.10.8≥ 16.1.0, < 16.1.6.1+1 more2025-10-15
CVE-2025-58153 [MEDIUM] CWE-667 CVE-2025-58153: Under undisclosed traffic conditions along with conditions beyond the attacker's control, hardware s
Under undisclosed traffic conditions along with conditions beyond the attacker's control, hardware systems with a High-Speed Bridge (HSB) may experience a lockup of the HSB.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2025-58474P4MEDIUMCVSS 5.3≥ 17.1.0, < 17.1.22025-10-15
CVE-2025-58474 [MEDIUM] CWE-770 CVE-2025-58474: When BIG-IP Advanced WAF is configured on a virtual server with Server-Side Request Forgery (SSRF) p
When BIG-IP Advanced WAF is configured on a virtual server with Server-Side Request Forgery (SSRF) protection or when an NGINX server is configured with App Protect Bot Defense, undisclosed requests can disrupt new client requests. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-40435P4MEDIUMCVSS 5.3≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+1 more2026-05-13
CVE-2026-40435 [MEDIUM] CWE-420 CVE-2026-40435: When configured, IP-based access restrictions for httpd do not cover all endpoints, which may allow
When configured, IP-based access restrictions for httpd do not cover all endpoints, which may allow connections from blocked addresses. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2014-8730P4MEDIUMCVSS 4.3v10.0.0v10.0.1+14 more2014-12-10
CVE-2014-8730 [MEDIUM] CVE-2014-8730: The SSL profiles component in F5 BIG-IP LTM, APM, and ASM 10.0.0 through 10.2.4 and 11.0.0 through 1
The SSL profiles component in F5 BIG-IP LTM, APM, and ASM 10.0.0 through 10.2.4 and 11.0.0 through 11.5.1, AAM 11.4.0 through 11.5.1, AFM 11.3.0 through 11.5.1, Analytics 11.0.0 through 11.5.1, Edge Gateway, WebAccelerator, and WOM 10.1.0 through 10.2.4 and 11.0.0 through 11.3.0, PEM 11.3.0 through 11.6.0, and PSM 10.0.0 through 10.2.4 and 11.0.0 through 11.4
nvd
CVE-2022-27878P4MEDIUMCVSS 6.8v13.1.0v13.1.1+16 more2022-05-05
CVE-2022-27878 [MEDIUM] CWE-79 CVE-2022-27878: On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP, and F5 BIG-IP Gu
On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP, and F5 BIG-IP Guided Configuration (GC) all versions prior to 9.0, a stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to execute JavaScript in the context of the currently logged-
nvd
CVE-2020-5903P4MEDIUMCVSS 6.1≥ 12.1.0, ≤ 12.1.5≥ 13.1.0, ≤ 13.1.3+2 more2020-07-01
CVE-2020-5903 [MEDIUM] CWE-79 CVE-2020-5903: In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, a Cross-Site
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, a Cross-Site Scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility.
nvd
CVE-2018-5505P4MEDIUMCVSS 5.9≥ 13.1.0, < 13.1.0.42018-03-22
CVE-2018-5505 [MEDIUM] CVE-2018-5505: On F5 BIG-IP versions 13.1.0 - 13.1.0.3, when ASM and AVR are both provisioned, TMM may restart whil
On F5 BIG-IP versions 13.1.0 - 13.1.0.3, when ASM and AVR are both provisioned, TMM may restart while processing DNS requests when the virtual server is configured with a DNS profile and the Protocol setting is set to TCP.
nvd
CVE-2016-9247P4MEDIUMCVSS 5.9v12.1.0v12.1.12017-01-10
CVE-2016-9247 [MEDIUM] CWE-20 CVE-2016-9247: Under certain conditions for BIG-IP systems using a virtual server with an associated FastL4 profile
Under certain conditions for BIG-IP systems using a virtual server with an associated FastL4 profile and TCP analytics profile, a specific sequence of packets may cause the Traffic Management Microkernel (TMM) to restart.
nvd
CVE-2016-9245P4MEDIUMCVSS 5.9v12.1.0v12.1.1+1 more2017-03-07
CVE-2016-9245 [MEDIUM] CWE-284 CVE-2016-9245: In F5 BIG-IP systems 12.1.0 - 12.1.2, malicious requests made to virtual servers with an HTTP profil
In F5 BIG-IP systems 12.1.0 - 12.1.2, malicious requests made to virtual servers with an HTTP profile can cause the TMM to restart. The issue is exposed with BIG-IP APM profiles, regardless of settings. The issue is also exposed with the non-default "Normalize URI" configuration options used in iRules and/or BIG-IP LTM policies. An attacker may be abl
nvd
CVE-2018-5500P4MEDIUMCVSS 5.9≥ 11.6.1, ≤ 11.6.2≥ 12.1.0, ≤ 12.1.3.1+1 more2018-03-01
CVE-2018-5500 [MEDIUM] CWE-400 CVE-2018-5500: On F5 BIG-IP systems running 13.0.0, 12.1.0 - 12.1.3.1, or 11.6.1 - 11.6.2, every Multipath TCP (MCT
On F5 BIG-IP systems running 13.0.0, 12.1.0 - 12.1.3.1, or 11.6.1 - 11.6.2, every Multipath TCP (MCTCP) connection established leaks a small amount of memory. Virtual server using TCP profile with Multipath TCP (MCTCP) feature enabled will be affected by this issue.
nvd
CVE-2021-22994P4MEDIUMCVSS 6.1≥ 11.6.1, < 11.6.5.3≥ 12.1.0, < 12.1.5.3+4 more2021-03-31
CVE-2021-22994 [MEDIUM] CVE-2021-22994: On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x befo
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, undisclosed endpoints in iControl REST allow for a reflected XSS attack, which could lead to a complete compromise of the BIG-IP system if the victim user is granted the admin role. This vulnera
nvd
CVE-2023-22418P4MEDIUMCVSS 6.1≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, < 14.1.5.3+3 more2023-02-01
CVE-2023-22418 [MEDIUM] CWE-601 CVE-2023-22418: On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.7, 14.1.x before 14.1
On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.7, 14.1.x before 14.1.5.3, and all versions of 13.1.x, an open redirect vulnerability exists on virtual servers enabled with a BIG-IP APM access policy. This vulnerability allows an unauthenticated malicious attacker to build an open redirect URI. Note: Software versions
nvd
CVE-2022-28708P4MEDIUMCVSS 5.9v15.1.0v15.1.1+7 more2022-05-05
CVE-2022-28708 [MEDIUM] CWE-20 CVE-2022-28708: On F5 BIG-IP 16.1.x versions prior to 16.1.2.2 and 15.1.x versions prior to 15.1.5.1, when a BIG-IP
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2 and 15.1.x versions prior to 15.1.5.1, when a BIG-IP DNS resolver-enabled, HTTP-Explicit or SOCKS profile is configured on a virtual server, an undisclosed DNS response can cause the Traffic Management Microkernel (TMM) process to terminate. Note: Software versions which have reached End of Technical Supp
nvd
CVE-2024-28889P4MEDIUMCVSS 5.9≥ 15.1.0, < 15.1.10.4≥ 16.1.0, < 16.1.4.3+1 more2024-05-08
CVE-2024-28889 [MEDIUM] CWE-825 CVE-2024-28889: When an SSL profile with alert timeout is configured with a non-default value on a virtual server
When an SSL profile with alert timeout is configured with a non-default value on a virtual server, undisclosed traffic along with conditions beyond the attacker's control can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd