cbcvebase.

F5 Big-Ip Domain Name System vulnerabilities

463 known vulnerabilities affecting f5/big-ip_domain_name_system.

Total CVEs
463
CISA KEV
8
actively exploited
Public exploits
11
Exploited in wild
11
Severity breakdown
CRITICAL32HIGH264MEDIUM163LOW4

Vulnerabilities

Page 3 of 24
CVE-2026-40061P3HIGHCVSS 8.7≥ 16.1.0, ≤ 16.1.6≥ 17.1.0, ≤ 17.1.3+2 more2026-05-13
CVE-2026-40061 [HIGH] CWE-77 CVE-2026-40061: When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iControl REST and BIG-IP TM When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system commands with higher privileges. In Appliance mode deployments, a successful exploit can allow the attacker
nvd
CVE-2016-5022P3CRITICALCVSS 9.8v12.0.02016-09-07
CVE-2016-5022 [CRITICAL] CWE-284 CVE-2016-5022: F5 BIG-IP LTM, Analytics, APM, ASM, and Link Controller 11.2.x before 11.2.1 HF16, 11.3.x, 11.4.x, 1 F5 BIG-IP LTM, Analytics, APM, ASM, and Link Controller 11.2.x before 11.2.1 HF16, 11.3.x, 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.6.1 HF1, and 12.x before 12.0.0 HF3; BIG-IP AAM, AFM, and PEM 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.6.1 HF1, and 12.x before 12.0.0 HF3; BIG-IP DNS 12.x before 12.0.0 HF3; BIG-IP Edge Gateway, Web
nvd
CVE-2021-22990P3HIGHCVSS 7.2≥ 11.6.1, < 11.6.5.3≥ 12.1.0, < 12.1.5.3+4 more2021-03-31
CVE-2021-22990 [HIGH] CVE-2021-22990: On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x befo On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, on systems with Advanced WAF or BIG-IP ASM provisioned, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has an authenticated remote command execution v
nvd
CVE-2017-6131P3CRITICALCVSS 9.8v12.0.0v12.1.0+3 more2017-05-23
CVE-2017-6131 [CRITICAL] CWE-798 CVE-2017-6131: In some circumstances, an F5 BIG-IP version 12.0.0 to 12.1.2 and 13.0.0 Azure cloud instance may con In some circumstances, an F5 BIG-IP version 12.0.0 to 12.1.2 and 13.0.0 Azure cloud instance may contain a default administrative password which could be used to remotely log into the BIG-IP system. The impacted administrative account is the Azure instance administrative user that was created at deployment. The root and admin accounts are not vulner
nvd
CVE-2026-41953P3HIGHCVSS 8.7≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+2 more2026-05-13
CVE-2026-41953 [HIGH] CWE-77 CVE-2026-41953: A vulnerability exists in BIG-IP systems where a highly privileged, authenticated attacker with at l A vulnerability exists in BIG-IP systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can modify configuration objects resulting in privilege escalation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-40631P3HIGHCVSS 8.7≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+2 more2026-05-13
CVE-2026-40631 [HIGH] CWE-552 CVE-2026-40631: An authenticated attacker with the Resource Administrator or Administrator role can modify configura An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects through iControl SOAP resulting in privilege escalation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-32643P3HIGHCVSS 8.7≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+2 more2026-05-13
CVE-2026-32643 [HIGH] CWE-250 CVE-2026-32643: A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacke A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-42406P3HIGHCVSS 8.7≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+2 more2026-05-13
CVE-2026-42406 [HIGH] CWE-267 CVE-2026-42406: A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacke A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2017-6165P3CRITICALCVSS 9.8v11.5.1v11.5.2+8 more2017-10-20
CVE-2017-6165 [CRITICAL] CWE-532 CVE-2017-6165: In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM, and WebSafe 11.5.1 In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM, and WebSafe 11.5.1 HF6 through 11.5.4 HF4, 11.6.0 through 11.6.1 HF1, and 12.0.0 through 12.1.2 on VIPRION platforms only, the script which synchronizes SafeNet External Network HSM configuration elements between blades in a clustered deployment will log the HSM partitio
nvd
CVE-2016-5020P3HIGHCVSS 8.8v12.0.02016-06-30
CVE-2016-5020 [HIGH] CWE-264 CVE-2016-5020: F5 BIG-IP before 12.0.0 HF3 allows remote authenticated users to modify the account configuration of F5 BIG-IP before 12.0.0 HF3 allows remote authenticated users to modify the account configuration of users with the Resource Administration role and gain privilege via a crafted external Extended Application Verification (EAV) monitor script.
nvd
CVE-2025-23239P3HIGHCVSS 8.7v17.1.12025-02-05
CVE-2025-23239 [HIGH] CWE-77 CVE-2025-23239: When running in Appliance mode, and logged into a highly-privileged role, an authenticated remote co When running in Appliance mode, and logged into a highly-privileged role, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2025-53868P3HIGHCVSS 8.7≥ 15.1.0, < 15.1.10.8≥ 16.1.0, < 16.1.6.1+2 more2025-10-15
CVE-2025-53868 [HIGH] CWE-78 CVE-2025-53868: When running in Appliance mode, a highly privileged authenticated attacker with access to SCP and SF When running in Appliance mode, a highly privileged authenticated attacker with access to SCP and SFTP may be able to bypass Appliance mode restrictions using undisclosed commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-40698P3HIGHCVSS 8.7≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+2 more2026-05-13
CVE-2026-40698 [HIGH] CWE-77 CVE-2026-40698: A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacke A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can create SNMP configuration objects through iControl REST or the TMOS shell (tmsh) resulting in privilege escalation. Note: Software versions which have reached End of Technical Support (EoTS) are not eva
nvd
CVE-2019-6649P3CRITICALCVSS 9.1≥ 11.5.2, ≤ 11.5.9≥ 11.6.1, ≤ 11.6.4+5 more2019-09-20
CVE-2019-6649 [CRITICAL] CVE-2019-6649: F5 BIG-IP 15.0.0, 14.1.0-14.1.0.6, 14.0.0-14.0.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, 11.6.0-11.6.4, F5 BIG-IP 15.0.0, 14.1.0-14.1.0.6, 14.0.0-14.0.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, 11.6.0-11.6.4, and 11.5.1-11.5.9 and Enterprise Manager 3.1.1 may expose sensitive information and allow the system configuration to be modified when using non-default ConfigSync settings.
nvd
CVE-2022-35243P3CRITICALCVSS 9.1≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, < 14.1.5+2 more2022-08-04
CVE-2022-35243 [CRITICAL] CWE-269 CVE-2022-35243: In BIG-IP Versions 16.1.x before 16.1.3, 15.1.x before 15.1.5.1, 14.1.x before 14.1.5, and all versi In BIG-IP Versions 16.1.x before 16.1.3, 15.1.x before 15.1.5.1, 14.1.x before 14.1.5, and all versions of 13.1.x, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, using an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross
nvd
CVE-2024-22093P3HIGHCVSS 8.7≥ 15.1.0, < 15.1.9≥ 16.1.0, < 16.1.4+1 more2024-02-14
CVE-2024-22093 [HIGH] CWE-77 CVE-2024-22093: When running in appliance mode, an authenticated remote command injection vulnerability exists in an When running in appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint on multi-bladed systems. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
CVE-2018-5506P3CRITICALCVSS 9.8≥ 11.5.1, ≤ 11.5.5≥ 12.1.0, ≤ 12.1.3.1+3 more2018-04-13
CVE-2018-5506 [CRITICAL] CVE-2018-5506: In F5 BIG-IP 13.0.0, 12.1.0-12.1.2, 11.6.1, 11.5.1-11.5.5, or 11.2.1 the Apache modules apache_auth_ In F5 BIG-IP 13.0.0, 12.1.0-12.1.2, 11.6.1, 11.5.1-11.5.5, or 11.2.1 the Apache modules apache_auth_token_mod and mod_auth_f5_auth_token.cpp allow possible unauthenticated bruteforce on the em_server_ip authorization parameter to obtain which SSL client certificates used for mutual authentication between BIG-IQ or Enterprise Manager (EM) and managed BIG-IP
nvd
CVE-2022-35728P3CRITICALCVSS 9.8≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, < 14.1.5.1+3 more2022-08-04
CVE-2022-35728 [CRITICAL] CWE-613 CVE-2022-35728: In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x be In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, and BIG-IQ version 8.x before 8.2.0 and all versions of 7.x, an authenticated user's iControl REST token may remain valid for a limited time after logging out from the Configuration utility. Note: Software
nvd
CVE-2019-6646P3HIGHCVSS 8.8≥ 11.5.2, ≤ 11.6.4v12.0.02019-09-04
CVE-2019-6646 [HIGH] CVE-2019-6646: On BIG-IP 11.5.2-11.6.4 and Enterprise Manager 3.1.1, REST users with guest privileges may be able t On BIG-IP 11.5.2-11.6.4 and Enterprise Manager 3.1.1, REST users with guest privileges may be able to escalate their privileges and run commands with admin privileges.
nvd
CVE-2019-10744P3CRITICALCVSS 9.1≥ 12.1.0, < 12.1.5.2≥ 13.1.0, < 13.1.3.4+3 more2019-07-26
CVE-2019-10744 [CRITICAL] CWE-1321 CVE-2019-10744: Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDe Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.
nvd
F5 Big-Ip Domain Name System vulnerabilities | cvebase