cbcvebase.

F5 Big-Ip Domain Name System vulnerabilities

463 known vulnerabilities affecting f5/big-ip_domain_name_system.

Total CVEs
463
CISA KEV
8
actively exploited
Public exploits
11
Exploited in wild
11
Severity breakdown
CRITICAL32HIGH264MEDIUM163LOW4

Vulnerabilities

Page 4 of 24
CVE-2020-5884P3CRITICALCVSS 9.1≥ 11.6.1, ≤ 11.6.5.1≥ 12.1.0, ≤ 12.1.5.1+3 more2020-04-30
CVE-2020-5884 [CRITICAL] CVE-2020-5884: On versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.4, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, On versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.4, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the default deployment mode for BIG-IP high availability (HA) pair mirroring is insecure. This is a control plane issue that is exposed only on the network used for mirroring.
nvd
CVE-2022-26415P3CRITICALCVSS 9.1≥ 12.1.0, ≤ 12.1.6≥ 13.1.0, < 13.1.5+3 more2022-05-05
CVE-2022-26415 [CRITICAL] CWE-77 CVE-2022-26415: On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions p On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing an undisclosed iControl
nvd
CVE-2022-34865P3CRITICALCVSS 9.1≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, < 14.1.5+1 more2022-08-04
CVE-2022-34865 [CRITICAL] CWE-295 CVE-2022-34865: In BIG-IP Versions 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, Traffic In BIG-IP Versions 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, Traffic Intelligence feeds, which use HTTPS, do not verify the remote endpoint identity, allowing for potential data poisoning. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2018-5504P3HIGHCVSS 8.1≥ 12.1.0, < 12.1.3.2≥ 13.0.0, ≤ 13.1.0.42018-03-22
CVE-2018-5504 [HIGH] CVE-2018-5504: In some circumstances, the Traffic Management Microkernel (TMM) does not properly handle certain mal In some circumstances, the Traffic Management Microkernel (TMM) does not properly handle certain malformed Websockets requests/responses, which allows remote attackers to cause a denial-of-service (DoS) or possible remote code execution on the F5 BIG-IP system running versions 13.0.0 - 13.1.0.3 or 12.1.0 - 12.1.3.1.
nvd
CVE-2026-39459P3HIGHCVSS 7.2≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+2 more2026-05-13
CVE-2026-39459 [HIGH] CWE-272 CVE-2026-39459: A vulnerability exists in iControl REST and the TMOS Shell (tmsh) where a highly privileged, authent A vulnerability exists in iControl REST and the TMOS Shell (tmsh) where a highly privileged, authenticated attacker with at least the Manager role can create configuration objects that allow running arbitrary commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-43746P3HIGHCVSS 8.7≥ 13.1.0, ≤ 14.1.5≥ 15.1.0, < 15.1.9+1 more2023-10-10
CVE-2023-43746 [HIGH] CWE-267 CVE-2023-43746: When running in Appliance mode, an authenticated user assigned the Administrator role may be able t When running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing BIG-IP external monitor on a BIG-IP system. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evalua
nvd
CVE-2019-6609P3CRITICALCVSS 9.8≥ 12.1.2, < 12.1.4.1≥ 13.0.0, < 13.1.1.4+2 more2019-04-15
CVE-2019-6609 [CRITICAL] CWE-522 CVE-2019-6609: Platform dependent weakness. This issue only impacts iSeries platforms. On these platforms, in BIG-I Platform dependent weakness. This issue only impacts iSeries platforms. On these platforms, in BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, FPS, GTM, Link Controller, PEM, WebAccelerator) versions 14.0.0-14.1.0.1, 13.0.0-13.1.1.3, and 12.1.1 HF2-12.1.4, the secureKeyCapable attribute was not set which causes secure vault to not use
nvd
CVE-2026-39455P3HIGHCVSS 7.5≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+2 more2026-05-13
CVE-2026-39455 [HIGH] CWE-772 CVE-2026-39455: When the BIG-IP Configuration utility is configured to use Lightweight Directory Access Protocol (LD When the BIG-IP Configuration utility is configured to use Lightweight Directory Access Protocol (LDAP) authentication, undisclosed traffic can cause the httpd process to exhaust the available file descriptors. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2019-6644P3CRITICALCVSS 9.4≥ 12.1.3, ≤ 12.1.4≥ 13.0.0, ≤ 13.1.2+2 more2019-09-04
CVE-2019-6644 [CRITICAL] CVE-2019-6644: Similar to the issue identified in CVE-2018-12120, on versions 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13. Similar to the issue identified in CVE-2018-12120, on versions 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.2, and 12.1.0-12.1.4 BIG-IP will bind a debug nodejs process to all interfaces when invoked. This may expose the process to unauthorized users if the plugin is left in debug mode and the port is accessible.
nvd
CVE-2021-22974P3HIGHCVSS 7.5≥ 13.1.0, < 13.1.3.6≥ 14.1.0, < 14.1.3.1+2 more2021-02-12
CVE-2021-22974 [HIGH] CVE-2021-22974: On BIG-IP version 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, and 13.1.x b On BIG-IP version 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, and 13.1.x before 13.1.3.6 and all versions of BIG-IQ 7.x and 6.x, an authenticated attacker with access to iControl REST over the control plane may be able to take advantage of a race condition to execute commands with an elevated privilege level. This vulnerability is du
nvd
CVE-2018-5743P3HIGHCVSS 7.5≥ 11.5.2, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.4+3 more2019-10-09
CVE-2018-5743 [HIGH] CWE-770 CVE-2018-5743: By design, BIND is intended to limit the number of TCP clients that can be connected at any given ti By design, BIND is intended to limit the number of TCP clients that can be connected at any given time. The number of allowed connections is a tunable parameter which, if unset, defaults to a conservative value for most servers. Unfortunately, the code which was intended to limit the number of simultaneous connections contained an error which could be e
nvd
CVE-2026-41218P3HIGHCVSS 7.5≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+2 more2026-05-13
CVE-2026-41218 [HIGH] CWE-416 CVE-2026-41218: When BIG-IP PEM iRules are configured on a virtual server (iRules using commands starting with CLASS When BIG-IP PEM iRules are configured on a virtual server (iRules using commands starting with CLASSIFICATION::, CLASSIFY::, PEM::, PSC::, and the urlcatquery command), undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2020-5885P3CRITICALCVSS 9.1≥ 12.1.0, ≤ 12.1.5.1≥ 13.1.0, ≤ 13.1.3.3+2 more2020-04-30
CVE-2020-5885 [CRITICAL] CWE-319 CVE-2020-5885: On versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, and 12.1.0-12.1.5.1, BIG-IP systems s On versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, and 12.1.0-12.1.5.1, BIG-IP systems set up for connection mirroring in a high availability (HA) pair transfer sensitive cryptographic objects over an insecure communications channel. This is a control plane issue which is exposed only on the network used for connection mirroring.
nvd
CVE-2020-5886P3CRITICALCVSS 9.1≥ 12.1.0, ≤ 12.1.5.1≥ 13.1.0, ≤ 13.1.3.3+2 more2020-04-30
CVE-2020-5886 [CRITICAL] CWE-319 CVE-2020-5886: On versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, and 12.1.0-12.1.5.1, BIG-IP systems s On versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, and 12.1.0-12.1.5.1, BIG-IP systems setup for connection mirroring in a High Availability (HA) pair transfers sensitive cryptographic objects over an insecure communications channel. This is a control plane issue which is exposed only on the network used for connection mirroring.
nvd
CVE-2016-9251P3HIGHCVSS 8.8v12.0.0v12.1.0+2 more2017-05-09
CVE-2016-9251 [HIGH] CWE-264 CVE-2016-9251: In F5 BIG-IP 12.0.0 through 12.1.2, an authenticated attacker may be able to cause an escalation of In F5 BIG-IP 12.0.0 through 12.1.2, an authenticated attacker may be able to cause an escalation of privileges through a crafted iControl REST connection.
nvd
CVE-2020-5906P3HIGHCVSS 8.1≥ 11.6.1, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.5+1 more2020-07-01
CVE-2020-5906 [HIGH] CWE-276 CVE-2020-5906: In versions 13.1.0-13.1.3.3, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, the BIG-IP system does not proper In versions 13.1.0-13.1.3.3, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, the BIG-IP system does not properly enforce the access controls for the scp.blacklist files. This allows Admin and Resource Admin users with Secure Copy (SCP) protocol access to read and overwrite blacklisted files via SCP.
nvd
CVE-2022-26071P3HIGHCVSS 7.5v11.6.1v11.6.2+29 more2022-05-05
CVE-2022-26071 [HIGH] CWE-330 CVE-2022-26071: On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions p On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, a flaw in the way reply ICMP packets are limited in the Traffic Management Microkernel (TMM) allows an attacker to quickly scan open UDP ports. This flaw allows an
nvd
CVE-2025-46706P3HIGHCVSS 7.5≥ 16.1.0, < 16.1.6≥ 17.1.0, < 17.1.2.22025-10-15
CVE-2025-46706 [HIGH] CWE-770 CVE-2025-46706: When an iRule containing the HTTP::respond command is configured on a virtual server, undisclosed re When an iRule containing the HTTP::respond command is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2020-5860P3HIGHCVSS 8.1≥ 11.5.2, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.5+3 more2020-03-27
CVE-2020-5860 [HIGH] CWE-287 CVE-2020-5860: On BIG-IP 15.0.0-15.1.0.2, 14.1.0-14.1.2.3, 13.1.0-13.1.3.2, 12.1.0-12.1.5.1, and 11.5.2-11.6.5.1 an On BIG-IP 15.0.0-15.1.0.2, 14.1.0-14.1.2.3, 13.1.0-13.1.3.2, 12.1.0-12.1.5.1, and 11.5.2-11.6.5.1 and BIG-IQ 7.0.0, 6.0.0-6.1.0, and 5.2.0-5.4.0, in a High Availability (HA) network failover in Device Service Cluster (DSC), the failover service does not require a strong form of authentication and HA network failover traffic is not encrypted by Transport
nvd
CVE-2021-23013P3HIGHCVSS 7.5≥ 12.1.0, < 12.1.5.3≥ 13.1.0, < 13.1.4+3 more2021-05-10
CVE-2021-23013 [HIGH] CVE-2021-23013: On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, the Traffic Management Microkernel (TMM) may stop responding when processing Stream Control Transmission Protocol (SCTP) traffic under certain conditions. This vulnerability affects TMM by way of a virtual server configure
nvd
F5 Big-Ip Domain Name System vulnerabilities | cvebase