cbcvebase.

F5 Big-Ip Asm vulnerabilities

471 known vulnerabilities affecting f5/big-ip_asm.

Total CVEs
471
CISA KEV
6
actively exploited
Public exploits
9
Exploited in wild
6
Severity breakdown
CRITICAL27HIGH275MEDIUM162LOW7

Vulnerabilities

Page 9 of 24
CVE-2022-23015HIGHCVSS 7.52022-01-25
CVE-2022-23015 [HIGH] CWE-400 CVE-2022-23015: On BIG-IP versions 16 CVE-2022-23015: On BIG-IP versions 16 On BIG-IP versions 16.x before 16.1.0, 15.1.x before 15.1.4.1, and 14.1.2.6-14.1.4.4, when a Client SSL profile is configured on a virtual server with Client Certificate Authentication set to request/require and Session Ticket enabled and configured, processing SSL traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Suppo
f5
CVE-2022-23010HIGHCVSS 7.52022-01-25
CVE-2022-23010 [HIGH] CWE-404 CVE-2022-23010: On BIG-IP versions 16 CVE-2022-23010: On BIG-IP versions 16 On BIG-IP versions 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x, 12.1.x, and 11.6.x, when a FastL4 profile and an HTTP profile are configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Affected P
f5
CVE-2022-23012HIGHCVSS 7.52022-01-25
CVE-2022-23012 [HIGH] CWE-415 CVE-2022-23012: On BIG-IP versions 15 CVE-2022-23012: On BIG-IP versions 15 On BIG-IP versions 15.1.x before 15.1.4.1 and 14.1.x before 14.1.4.5, when the HTTP/2 profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Affected Products: BIG-IP AAM, BIG-IP AFM, BIG-IP APM, BIG-IP ASM, BIG-IP Analytics
f5
CVE-2022-23020HIGHCVSS 7.52022-01-25
CVE-2022-23020 [HIGH] CWE-476 CVE-2022-23020: On BIG-IP version 16 CVE-2022-23020: On BIG-IP version 16 On BIG-IP version 16.1.x before 16.1.2, when the 'Respond on Error' setting is enabled on the Request Logging profile and configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Affected Products: BIG-IP AAM, BIG-IP AFM, BIG-IP APM, BIG-I
f5
CVE-2022-23025HIGHCVSS 7.52022-01-25
CVE-2022-23025 [HIGH] CWE-476 CVE-2022-23025: On BIG-IP version 16 CVE-2022-23025: On BIG-IP version 16 On BIG-IP version 16.1.x before 16.1.1, 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, and all versions of 13.1.x, when a SIP ALG profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Affected Products: BIG-IP AAM, BIG-IP AFM,
f5
CVE-2022-23017HIGHCVSS 7.52022-01-25
CVE-2022-23017 [HIGH] CWE-476 CVE-2022-23017: On BIG-IP version 16 CVE-2022-23017: On BIG-IP version 16 On BIG-IP version 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versions of 13.1.x, when a virtual server is configured with a DNS profile with the Rapid Response Mode setting enabled and is configured on a BIG-IP system, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technic
f5
CVE-2022-23021HIGHCVSS 7.52022-01-25
CVE-2022-23021 [HIGH] CWE-476 CVE-2022-23021: On BIG-IP version 16 CVE-2022-23021: On BIG-IP version 16 On BIG-IP version 16.1.x before 16.1.2, when any of the following configurations are configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate: HTTP redirect rule in an LTM policy, BIG-IP APM Access Profile, and Explicit HTTP Proxy in HTTP Profile. Note: Software versions which have reached End of Technical Support (EoTS) are not eval
f5
CVE-2022-23030MEDIUMCVSS 5.32022-01-25
CVE-2022-23030 [MEDIUM] CWE-400 CVE-2022-23030: On version 16 CVE-2022-23030: On version 16 On version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versions of 13.1.x, when the BIG-IP Virtual Edition (VE) uses the ixlv driver (which is used in SR-IOV mode and requires Intel X710/XL710/XXV710 family of network adapters on the Hypervisor) and TCP Segmentation Offload configuration is enabled, undisclosed requests may cause an increase in CPU resource utilization.
f5
CVE-2022-23029MEDIUMCVSS 5.32022-01-25
CVE-2022-23029 [MEDIUM] CWE-367 CVE-2022-23029: On BIG-IP version 16 CVE-2022-23029: On BIG-IP version 16 On BIG-IP version 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x, 12.1.x, and 11.6.x, when a FastL4 profile is configured on a virtual server, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Affected Products: BIG-IP AAM, BI
f5
CVE-2022-23023MEDIUMCVSS 6.52022-01-25
CVE-2022-23023 [MEDIUM] CWE-400 CVE-2022-23023: On BIG-IP version 16 CVE-2022-23023: On BIG-IP version 16 On BIG-IP version 16.1.x before 16.1.2.1, 15.1.x before 15.1.5, 14.1.x before 14.1.4.5, and all versions of 13.1.x and 12.1.x, and BIG-IQ all versions of 8.x and 7.x, undisclosed requests by an authenticated iControl REST user can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Affected Products
f5
CVE-2022-23031MEDIUMCVSS 4.92022-01-25
CVE-2022-23031 [MEDIUM] CWE-611 CVE-2022-23031: On BIG-IP FPS, ASM, and Advanced WAF versions 16 CVE-2022-23031: On BIG-IP FPS, ASM, and Advanced WAF versions 16 On BIG-IP FPS, ASM, and Advanced WAF versions 16.1.x before 16.1.1, 15.1.x before 15.1.4, and 14.1.x before 14.1.4.4, an XML External Entity (XXE) vulnerability exists in an undisclosed page of the F5 Advanced Web Application Firewall (Advanced WAF) and BIG-IP ASM Traffic Management User Interface (TMUI), also referred to as the Config
f5
CVE-2022-23027MEDIUMCVSS 5.32022-01-25
CVE-2022-23027 [MEDIUM] CWE-697 CVE-2022-23027: On BIG-IP versions 15 CVE-2022-23027: On BIG-IP versions 15 On BIG-IP versions 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, 13.1.x beginning in 13.1.3.6, 12.1.5.3-12.1.6, and 11.6.5.2, when a FastL4 profile and an HTTP, FIX, and/or hash persistence profile are configured on the same virtual server, undisclosed requests can cause the virtual server to stop processing new client connections. Note: Software versions which have reached End of Technic
f5
CVE-2022-23026MEDIUMCVSS 4.32022-01-25
CVE-2022-23026 [MEDIUM] CWE-434 CVE-2022-23026: On BIG-IP ASM & Advanced WAF version 16 CVE-2022-23026: On BIG-IP ASM & Advanced WAF version 16 On BIG-IP ASM & Advanced WAF version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versions of 13.1.x and 12.1.x, an authenticated user with low privileges, such as a guest, can upload data using an undisclosed REST endpoint causing an increase in disk resource utilization. Note: Software versions which have reached End o
f5
CVE-2021-23037CRITICALCVSS 9.62021-09-14
CVE-2021-23037 [CRITICAL] CWE-79 CVE-2021-23037: On all versions of 16 CVE-2021-23037: On all versions of 16 On all versions of 16.1.x, 16.0.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x, a reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to execute JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Aff
f5
CVE-2021-23031CRITICALCVSS 9.92021-09-14
CVE-2021-23031 [CRITICAL] CWE-78 CVE-2021-23031: On version 16 CVE-2021-23031: On version 16 On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.1, 13.1.x before 13.1.4, 12.1.x before 12.1.6, and 11.6.x before 11.6.5.3, an authenticated user may perform a privilege escalation on the BIG-IP Advanced WAF and ASM Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Affected Products: BIG-IP ASM, BIG-IP Advan
f5
CVE-2021-23038CRITICALCVSS 9.02021-09-14
CVE-2021-23038 [CRITICAL] CWE-79 CVE-2021-23038: On version 16 CVE-2021-23038: On version 16 On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x, a stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to execute JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical S
f5
CVE-2021-23048HIGHCVSS 7.52021-09-14
CVE-2021-23048 [HIGH] CWE-20 CVE-2021-23048: On BIG-IP version 16 CVE-2021-23048: On BIG-IP version 16 On BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, 13.1.x before 13.1.4.1, and all versions of 12.1.x and 11.6.x, when GPRS Tunneling Protocol (GTP) iRules commands or a GTP profile is configured on a virtual server, undisclosed GTP messages can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of
f5
CVE-2021-23050HIGHCVSS 7.52021-09-14
CVE-2021-23050 [HIGH] CWE-352 CVE-2021-23050: On BIG-IP Advanced WAF and BIG-IP ASM version 16 CVE-2021-23050: On BIG-IP Advanced WAF and BIG-IP ASM version 16 On BIG-IP Advanced WAF and BIG-IP ASM version 16.0.x before 16.0.1.2 and 15.1.x before 15.1.3 and NGINX App Protect on all versions before 3.5.0, when a cross-site request forgery (CSRF)-enabled policy is configured on a virtual server, an undisclosed HTML response may cause the bd process to terminate. Note: Software versions which have
f5
CVE-2021-23039HIGHCVSS 7.52021-09-14
CVE-2021-23039 [HIGH] CWE-20 CVE-2021-23039: On version 16 CVE-2021-23039: On version 16 On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.2.8, and all versions of 13.1.x and 12.1.x, when IPSec is configured on a BIG-IP system, undisclosed requests from an authorized remote (IPSec) peer, which already has a negotiated Security Association, can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Suppor
f5
CVE-2021-23030HIGHCVSS 7.52021-09-14
CVE-2021-23030 [HIGH] CWE-20 CVE-2021-23030: On BIG-IP Advanced WAF and BIG-IP ASM version 16 CVE-2021-23030: On BIG-IP Advanced WAF and BIG-IP ASM version 16 On BIG-IP Advanced WAF and BIG-IP ASM version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, 13.1.x before 13.1.4.1, and all versions of 12.1.x, when a WebSocket profile is configured on a virtual server, undisclosed requests can cause bd to terminate. Note: Software versions which have reached End of Technical Su
f5