F5 Big-Ip Asm vulnerabilities
471 known vulnerabilities affecting f5/big-ip_asm.
Total CVEs
471
CISA KEV
6
actively exploited
Public exploits
9
Exploited in wild
6
Severity breakdown
CRITICAL27HIGH275MEDIUM162LOW7
Vulnerabilities
Page 11 of 24
CVE-2021-23015HIGHCVSS 7.22021-05-10
CVE-2021-23015 [HIGH] CWE-863 CVE-2021-23015: On BIG-IP 15
CVE-2021-23015: On BIG-IP 15
On BIG-IP 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.0.8 through 13.1.3.6, and all versions of 16.0.x, when running in Appliance Mode, an authenticated user assigned the 'Administrator' role may be able to bypass Appliance Mode restrictions utilizing undisclosed iControl REST endpoints. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Products: B
f5
CVE-2021-23010HIGHCVSS 7.52021-05-10
CVE-2021-23010 [HIGH] CVE-2021-23010: On versions 16
CVE-2021-23010: On versions 16
On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.5, and 12.1.x before 12.1.5.3, when the BIG-IP ASM/Advanced WAF system processes WebSocket requests with JSON payloads using the default JSON Content Profile in the ASM Security Policy, the BIG-IP ASM bd process may produce a core file. Note: Software versions which have reached End of Technical Support (EoTS)
f5
CVE-2021-23013HIGHCVSS 7.52021-05-10
CVE-2021-23013 [HIGH] CVE-2021-23013: On BIG-IP versions 16
CVE-2021-23013: On BIG-IP versions 16
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, the Traffic Management Microkernel (TMM) may stop responding when processing Stream Control Transmission Protocol (SCTP) traffic under certain conditions. This vulnerability affects TMM by way of a virtual server configured with an SCTP profile. Note: Software v
f5
CVE-2021-23012HIGHCVSS 8.22021-05-10
CVE-2021-23012 [HIGH] CWE-78 CVE-2021-23012: On BIG-IP versions 16
CVE-2021-23012: On BIG-IP versions 16
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, and 13.1.x before 13.1.4, lack of input validation for items used in the system support functionality may allow users granted either "Resource Administrator" or "Administrator" roles to execute arbitrary bash commands on BIG-IP. Note: Software versions which have reached End of Technical Support (EoTS) are
f5
CVE-2021-22987CRITICALCVSS 9.92021-03-31
CVE-2021-22987 [CRITICAL] CVE-2021-22987: On BIG-IP versions 16
CVE-2021-22987: On BIG-IP versions 16
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3 when running in Appliance mode, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has an authenticated remote command execution vulnerability in undisclosed pages. Note: Software versions wh
f5
CVE-2021-22989CRITICALCVSS 9.12021-03-31
CVE-2021-22989 [CRITICAL] CVE-2021-22989: On BIG-IP versions 16
CVE-2021-22989: On BIG-IP versions 16
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, when running in Appliance mode with Advanced WAF or BIG-IP ASM provisioned, the TMUI, also referred to as the Configuration utility, has an authenticated remote command execution vulnerability in undisclosed pages. Note: Software ve
f5
CVE-2021-22991CRITICALCVSS 9.8KEV2021-03-31
CVE-2021-22991 [CRITICAL] CWE-119 CVE-2021-22991: On BIG-IP versions 16
CVE-2021-22991: On BIG-IP versions 16
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, undisclosed requests to a virtual server may be incorrectly handled by the Traffic Management Microkernel (TMM) URI normalization, which may trigger a buffer overflow, resulting in a DoS attack. In certain situations, it may theoretically allow byp
f5
CVE-2021-22986CRITICALCVSS 9.8KEVPoC2021-03-31
CVE-2021-22986 [CRITICAL] CWE-918 CVE-2021-22986: On BIG-IP versions 16
CVE-2021-22986: On BIG-IP versions 16
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an unauthenticated remote command execution vulnerability. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
f5
CVE-2021-22992CRITICALCVSS 9.82021-03-31
CVE-2021-22992 [CRITICAL] CWE-120 CVE-2021-22992: On BIG-IP versions 16
CVE-2021-22992: On BIG-IP versions 16
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, a malicious HTTP response to an Advanced WAF/BIG-IP ASM virtual server with Login Page configured in its policy may trigger a buffer overflow, resulting in a DoS attack. In certain situations, it may allow remote code execut
f5
CVE-2021-22990HIGHCVSS 7.22021-03-31
CVE-2021-22990 [HIGH] CVE-2021-22990: On BIG-IP versions 16
CVE-2021-22990: On BIG-IP versions 16
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, on systems with Advanced WAF or BIG-IP ASM provisioned, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has an authenticated remote command execution vulnerability in undisclosed pages. Note:
f5
CVE-2021-23003HIGHCVSS 7.52021-03-31
CVE-2021-23003 [HIGH] CVE-2021-23003: On BIG-IP versions 16
CVE-2021-23003: On BIG-IP versions 16
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, the Traffic Management Microkernel (TMM) process may produce a core file when undisclosed MPTCP traffic passes through a standard virtual server. Note: Software versions which have reached End of Software Development (EoSD) are not eval
f5
CVE-2021-22988HIGHCVSS 8.82021-03-31
CVE-2021-22988 [HIGH] CVE-2021-22988: On BIG-IP versions 16
CVE-2021-22988: On BIG-IP versions 16
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, TMUI, also referred to as the Configuration utility, has an authenticated remote command execution vulnerability in undisclosed pages. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Aff
f5
CVE-2021-23000HIGHCVSS 7.52021-03-31
CVE-2021-23000 [HIGH] CVE-2021-23000: On BIG-IP versions 13
CVE-2021-23000: On BIG-IP versions 13
On BIG-IP versions 13.1.3.4-13.1.3.6 and 12.1.5.2, if the tmm.http.rfc.enforcement BigDB key is enabled in a BIG-IP system, or the Bad host header value is checked in the AFM HTTP security profile associated with a virtual server, in rare instances, a specific sequence of malicious requests may cause TMM to restart. Note: Software versions which have reached End of Software Development (EoSD) are n
f5
CVE-2021-22993HIGHCVSS 8.82021-03-31
CVE-2021-22993 [HIGH] CWE-79 CVE-2021-22993: On BIG-IP Advanced WAF and BIG-IP ASM versions 16
CVE-2021-22993: On BIG-IP Advanced WAF and BIG-IP ASM versions 16
On BIG-IP Advanced WAF and BIG-IP ASM versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, DOM-based XSS on DoS Profile properties page. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Affected Products: BIG-IP
f5
CVE-2021-22999HIGHCVSS 7.52021-03-31
CVE-2021-22999 [HIGH] CVE-2021-22999: On versions 15
CVE-2021-22999: On versions 15
On versions 15.0.x before 15.1.0 and 14.1.x before 14.1.4, the BIG-IP system provides an option to connect HTTP/2 clients to HTTP/1.x servers. When a client is slow to accept responses and it closes a connection prematurely, the BIG-IP system may indefinitely retain some streams unclosed. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Affected Products: BIG-IP A
f5
CVE-2021-23004HIGHCVSS 7.52021-03-31
CVE-2021-23004 [HIGH] CVE-2021-23004: On BIG-IP versions 16
CVE-2021-23004: On BIG-IP versions 16
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, Multipath TCP (MPTCP) forwarding flows may be created on standard virtual servers without MPTCP enabled in the applied TCP profile. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Affect
f5
CVE-2021-23001MEDIUMCVSS 4.32021-03-31
CVE-2021-23001 [MEDIUM] CWE-434 CVE-2021-23001: On versions 16
CVE-2021-23001: On versions 16
On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, the upload functionality in BIG-IP Advanced WAF and BIG-IP ASM allows an authenticated user to upload files to the BIG-IP system using a call to an undisclosed iControl REST endpoint. Note: Software versions which have reached End of Software Deve
f5
CVE-2021-22994MEDIUMCVSS 6.12021-03-31
CVE-2021-22994 [CRITICAL] CWE-79 CVE-2021-22994: On BIG-IP versions 16
CVE-2021-22994: On BIG-IP versions 16
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, undisclosed endpoints in iControl REST allow for a reflected XSS attack, which could lead to a complete compromise of the BIG-IP system if the victim user is granted the admin role. This vulnerability is due to an incomplete
f5
CVE-2021-22998MEDIUMCVSS 5.32021-03-31
CVE-2021-22998 [MEDIUM] CVE-2021-22998: On BIG-IP versions 16
CVE-2021-22998: On BIG-IP versions 16
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, SYN flood protection thresholds are not enforced in secure network address translation (SNAT) listeners. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Affected Products: BIG-IP AAM,
f5
CVE-2021-23007MEDIUMCVSS 5.32021-03-31
CVE-2021-23007 [MEDIUM] CVE-2021-23007: On BIG-IP versions 14
CVE-2021-23007: On BIG-IP versions 14
On BIG-IP versions 14.1.4 and 16.0.1.1, when the Traffic Management Microkernel (TMM) process handles certain undisclosed traffic, it may start dropping all fragmented IP traffic. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Affected Products: BIG-IP AAM, BIG-IP AFM, BIG-IP APM, BIG-IP ASM, BIG-IP Advanced WAF, BIG-IP Analytics, BIG-IP DHD, BIG
f5