cbcvebase.

F5 Big-Ip Global Traffic Manager vulnerabilities

484 known vulnerabilities affecting f5/big-ip_global_traffic_manager.

Total CVEs
484
CISA KEV
11
actively exploited
Public exploits
20
Exploited in wild
13
Severity breakdown
CRITICAL38HIGH268MEDIUM174LOW4

Vulnerabilities

Page 20 of 25
CVE-2021-22979P4MEDIUMCVSS 6.1≥ 12.1.0, ≤ 12.1.5≥ 13.1.0, < 13.1.3.5+3 more2021-02-12
CVE-2021-22979 [MEDIUM] CWE-79 CVE-2021-22979: On BIG-IP version 16.0.x before 16.0.1, 15.1.x before 15.1.1, 14.1.x before 14.1.2.8, 13.1.x before On BIG-IP version 16.0.x before 16.0.1, 15.1.x before 15.1.1, 14.1.x before 14.1.2.8, 13.1.x before 13.1.3.5, and all 12.1.x versions, a reflected Cross-Site Scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility when Fraud Protection Service is provisioned and allows an attacker to execute JavaScript in the co
nvd
CVE-2020-5935P4MEDIUMCVSS 5.9≥ 13.1.0, < 13.1.3.4≥ 14.1.0, < 14.1.2.4+1 more2020-10-29
CVE-2020-5935 [MEDIUM] CVE-2020-5935: On BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, FPS, GTM, Link Controller, PEM) versions 15.1.0- On BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, FPS, GTM, Link Controller, PEM) versions 15.1.0-15.1.0.5, 14.1.0-14.1.2.3, and 13.1.0-13.1.3.3, when handling MQTT traffic through a BIG-IP virtual server associated with an MQTT profile and an iRule performing manipulations on that traffic, TMM may produce a core file.
nvd
CVE-2025-59269P4MEDIUMCVSS 6.1≥ 15.1.0, < 15.1.10.8≥ 16.1.0, < 16.1.6.1+1 more2025-10-15
CVE-2025-59269 [MEDIUM] CWE-79 CVE-2025-59269: A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Config A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2024-23976P4MEDIUMCVSS 6.0≥ 15.1.0, < 15.1.9≥ 16.1.0, < 16.1.4+1 more2024-02-14
CVE-2024-23976 [MEDIUM] CWE-266 CVE-2024-23976: When running in Appliance mode, an authenticated attacker assigned the Administrator role may be abl When running in Appliance mode, an authenticated attacker assigned the Administrator role may be able to bypass Appliance mode restrictions utilizing iAppsLX templates on a BIG-IP system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
CVE-2019-6651P4MEDIUMCVSS 5.3≥ 11.5.1, ≤ 11.6.4≥ 12.1.0, ≤ 12.1.4.1+4 more2019-09-25
CVE-2019-6651 [MEDIUM] CWE-203 CVE-2019-6651: In BIG-IP 15.0.0, 14.1.0-14.1.0.6, 14.0.0-14.0.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, 11.5.1-11.6.4, In BIG-IP 15.0.0, 14.1.0-14.1.0.6, 14.0.0-14.0.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, 11.5.1-11.6.4, BIG-IQ 7.0.0, 6.0.0-6.1.0,5.2.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1, the Configuration utility login page may not follow best security practices when handling a malicious request.
nvd
CVE-2022-26130P4MEDIUMCVSS 5.3v13.1.0v13.1.1+16 more2022-05-05
CVE-2022-26130 [MEDIUM] CWE-754 CVE-2022-26130: On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions p On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, when an Active mode-enabled FTP profile is configured on a virtual server, undisclosed traffic can cause the virtual server to stop processing active FTP data channel connections. Note: Software v
nvd
CVE-2022-29480P4MEDIUMCVSS 5.3v11.6.1v11.6.2+29 more2022-05-05
CVE-2022-29480 [MEDIUM] CWE-400 CVE-2022-29480: On F5 BIG-IP 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, when multiple r On F5 BIG-IP 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, when multiple route domains are configured, undisclosed requests to big3d can cause an increase in CPU resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
CVE-2022-29479P4MEDIUMCVSS 5.3v11.6.1v11.6.2+29 more2022-05-05
CVE-2022-29479 [MEDIUM] CWE-20 CVE-2022-29479: On F5 BIG-IP 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions p On F5 BIG-IP 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, and F5 BIG-IQ Centralized Management all versions of 8.x and 7.x, when an IPv6 self IP address is configured and the ipv6.strictcompliance database key is enabled (disabled by default) on a BIG-IP
nvd
CVE-2022-27182P4MEDIUMCVSS 5.3v14.1.0v14.1.2+11 more2022-05-05
CVE-2022-27182 [MEDIUM] CWE-400 CVE-2022-27182: On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, and 14.1.x versio On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, and 14.1.x versions prior to 14.1.4.6, when BIG-IP packet filters are enabled and a virtual server is configured with the type set to Reject, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of T
nvd
CVE-2019-19151P4MEDIUMCVSS 5.5≥ 11.5.1, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.5+3 more2019-12-23
CVE-2019-19151 [MEDIUM] CWE-269 CVE-2019-19151: On BIG-IP versions 15.0.0-15.1.0, 14.0.0-14.1.2.3, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.5.2-11.6.5 On BIG-IP versions 15.0.0-15.1.0, 14.0.0-14.1.2.3, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, BIG-IQ versions 7.0.0, 6.0.0-6.1.0, and 5.0.0-5.4.0, iWorkflow version 2.3.0, and Enterprise Manager version 3.1.1, authenticated users granted TMOS Shell (tmsh) privileges are able access objects on the file system which would normally be disallo
nvd
CVE-2025-54500P4MEDIUMCVSS 5.3≥ 15.1.0, < 15.1.10.8≥ 16.1.0, < 16.1.6.1+1 more2025-08-13
CVE-2025-54500 [MEDIUM] CWE-770 CVE-2025-54500: An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control fr An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit (HTTP/2 MadeYouReset Attack). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-42063P4MEDIUMCVSS 4.9≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+2 more2026-05-13
CVE-2026-42063 [MEDIUM] CWE-552 CVE-2026-42063: A vulnerability exists in iControl SOAP where an authenticated attacker with the Resource Administra A vulnerability exists in iControl SOAP where an authenticated attacker with the Resource Administrator or Administrator role can download sensitive files. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-42781P4MEDIUMCVSS 6.5v21.0.0≥ 17.1.0, ≤ 17.1.3+1 more2026-05-13
CVE-2026-42781 [MEDIUM] CWE-835 CVE-2026-42781: When embedded Packet Velocity Acceleration (ePVA) acceleration is configured, undisclosed local ethe When embedded Packet Velocity Acceleration (ePVA) acceleration is configured, undisclosed local ethernet traffic can cause an increase in ePVA and Traffic Management Microkernel (TMM) resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2021-23027P4MEDIUMCVSS 6.1≥ 14.1.0, ≤ 14.1.4≥ 15.1.0, ≤ 15.1.3+1 more2021-09-14
CVE-2021-23027 [MEDIUM] CWE-79 CVE-2021-23027: On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, and 14.1.x before 14.1.4.3, a DOM based c On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, and 14.1.x before 14.1.4.3, a DOM based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to execute JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Te
nvd
CVE-2019-6608P4MEDIUMCVSS 5.9≥ 11.2.1, ≤ 11.6.3≥ 12.1.0, ≤ 12.1.3+2 more2019-03-28
CVE-2019-6608 [MEDIUM] CWE-401 CVE-2019-6608: On BIG-IP 11.5.1-11.6.3, 12.1.0-12.1.3, 13.0.0-13.1.1.1, and 14.0.0-14.0.0.2, under certain conditio On BIG-IP 11.5.1-11.6.3, 12.1.0-12.1.3, 13.0.0-13.1.1.1, and 14.0.0-14.0.0.2, under certain conditions, the snmpd daemon may leak memory on a multi-blade BIG-IP vCMP guest when processing authorized SNMP requests.
nvd
CVE-2019-6594P4MEDIUMCVSS 5.9≥ 11.5.1, ≤ 11.6.3.2≥ 12.1.3.4, ≤ 12.1.3.7+3 more2019-02-26
CVE-2019-6594 [MEDIUM] CWE-835 CVE-2019-6594: On BIG-IP 11.5.1-11.6.3.2, 12.1.3.4-12.1.3.7, 13.0.0 HF1-13.1.1.1, and 14.0.0-14.0.0.2, Multi-Path T On BIG-IP 11.5.1-11.6.3.2, 12.1.3.4-12.1.3.7, 13.0.0 HF1-13.1.1.1, and 14.0.0-14.0.0.2, Multi-Path TCP (MPTCP) does not protect against multiple zero length DATA_FINs in the reassembly queue, which can lead to an infinite loop in some circumstances.
nvd
CVE-2014-5209P4MEDIUMCVSS 5.3≥ 10.2.1, ≤ 10.2.4≥ 11.4.0, ≤ 11.6.4+1 more2020-01-08
CVE-2014-5209 [MEDIUM] CWE-200 CVE-2014-5209: An Information Disclosure vulnerability exists in NTP 4.2.7p25 private (mode 6/7) messages via a GET An Information Disclosure vulnerability exists in NTP 4.2.7p25 private (mode 6/7) messages via a GET_RESTRICT control message, which could let a malicious user obtain sensitive information.
nvd
CVE-2019-6640P4MEDIUMCVSS 5.3≥ 11.5.1, < 11.5.9≥ 11.6.1, < 11.6.4+4 more2019-07-03
CVE-2019-6640 [MEDIUM] CWE-319 CVE-2019-6640: On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11. On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.1-11.5.8, SNMP exposes sensitive configuration objects over insecure transmission channels. This issue is exposed when a passphrase is inserted into various profile types and accessed using SNMPv2.
nvd
CVE-2015-4638P4MEDIUMCVSS 5.0v11.3.0v11.4.0+5 more2015-09-18
CVE-2015-4638 [MEDIUM] CWE-20 CVE-2015-4638: The FastL4 virtual server in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, GTM, Link Controller, and The FastL4 virtual server in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, GTM, Link Controller, and PEM 11.3.0 through 11.5.2 and 11.6.0 through 11.6.0 HF4, BIG-IP Edge Gateway, WebAccelerator, and WOM 11.2.1 through 11.3.0, and BIG-IP PSM 11.2.1 through 11.4.1 allows remote attackers to cause a denial of service (Traffic Management Microkernel restar
nvd
CVE-2020-5890P4MEDIUMCVSS 5.5≥ 12.1.0, ≤ 12.1.5.1≥ 13.1.0, ≤ 13.1.3.3+2 more2020-04-30
CVE-2020-5890 [MEDIUM] CWE-200 CVE-2020-5890: On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, and 12.1.0-12.1.5.1 and BIG-IQ 5.2.0-7.1. On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, and 12.1.0-12.1.5.1 and BIG-IQ 5.2.0-7.1.0, when creating a QKView, credentials for binding to LDAP servers used for remote authentication of the BIG-IP administrative interface will not fully obfuscate if they contain whitespace.
nvd