cbcvebase.

F5 Big-Ip Global Traffic Manager vulnerabilities

484 known vulnerabilities affecting f5/big-ip_global_traffic_manager.

Total CVEs
484
CISA KEV
11
actively exploited
Public exploits
20
Exploited in wild
13
Severity breakdown
CRITICAL38HIGH268MEDIUM174LOW4

Vulnerabilities

Page 24 of 25
CVE-2019-6606P4MEDIUMCVSS 4.3≥ 11.5.1, ≤ 11.6.3.4≥ 12.1.0, ≤ 12.1.3.7+2 more2019-03-28
CVE-2019-6606 [MEDIUM] CWE-401 CVE-2019-6606: On BIG-IP 11.5.1-11.6.3.4, 12.1.0-12.1.3.7, 13.0.0-13.1.1.3, and 14.0.0-14.0.0.2, when processing ce On BIG-IP 11.5.1-11.6.3.4, 12.1.0-12.1.3.7, 13.0.0-13.1.1.3, and 14.0.0-14.0.0.2, when processing certain SNMP requests with a request-id of 0, the snmpd process may leak a small amount of memory.
nvd
CVE-2024-27202P4MEDIUMCVSS 4.7≥ 15.1.0, < 15.1.10.4≥ 16.1.0, < 16.1.4.3+1 more2024-05-08
CVE-2024-27202 [MEDIUM] CWE-79 CVE-2024-27202: A DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Co A DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2019-6598P4MEDIUMCVSS 4.3≥ 11.5.1, ≤ 11.5.8≥ 11.6.1, ≤ 11.6.3.2+3 more2019-03-13
CVE-2019-6598 [MEDIUM] CVE-2019-6598: In BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, 11.6.1-11.6.3.2, or 11.5.1-11.5.8 or En In BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, 11.6.1-11.6.3.2, or 11.5.1-11.5.8 or Enterprise Manager 3.1.1, malformed requests to the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, may lead to disruption of TMUI services. This attack requires an authenticated user with any role (other than the N
nvd
CVE-2020-5947P4MEDIUMCVSS 4.3≥ 15.0.0, ≤ 15.1.2≥ 16.0.0, < 16.0.12020-11-19
CVE-2020-5947 [MEDIUM] CVE-2020-5947: In versions 16.0.0-16.0.0.1 and 15.1.0-15.1.1, on specific BIG-IP platforms, attackers may be able t In versions 16.0.0-16.0.0.1 and 15.1.0-15.1.1, on specific BIG-IP platforms, attackers may be able to obtain TCP sequence numbers from the BIG-IP system that can be reused in future connections with the same source and destination port and IP numbers. Only these platforms are affected: BIG-IP 2000 series (C112), BIG-IP 4000 series (C113), BIG-IP i2000 series
nvd
CVE-2023-38419P4MEDIUMCVSS 4.3≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, < 14.1.5.5+3 more2023-08-02
CVE-2023-38419 [MEDIUM] CWE-755 CVE-2023-38419: An authenticated attacker with guest privileges or higher can cause the iControl SOAP process to ter An authenticated attacker with guest privileges or higher can cause the iControl SOAP process to terminate by sending undisclosed requests. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2019-6654P4MEDIUMCVSS 4.3≥ 11.5.1, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.5+2 more2019-09-25
CVE-2019-6654 [MEDIUM] CWE-20 CVE-2019-6654: On versions 14.0.0-14.1.2, 13.0.0-13.1.3, 12.1.0-12.1.5, and 11.5.1-11.6.5, the BIG-IP system fails On versions 14.0.0-14.1.2, 13.0.0-13.1.3, 12.1.0-12.1.5, and 11.5.1-11.6.5, the BIG-IP system fails to perform Martian Address Filtering (As defined in RFC 1812 section 5.3.7) on the control plane (management interface). This may allow attackers on an adjacent system to force BIG-IP into processing packets with spoofed source addresses.
nvd
CVE-2024-41723P4MEDIUMCVSS 4.3≥ 15.1.0, ≤ 15.1.1≥ 16.1.0, < 16.1.5+1 more2024-08-14
CVE-2024-41723 [MEDIUM] CWE-200 CVE-2024-41723: Undisclosed requests to BIG-IP iControl REST can lead to information leak of user account names. No Undisclosed requests to BIG-IP iControl REST can lead to information leak of user account names. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-42058P4MEDIUMCVSS 4.3≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+2 more2026-05-13
CVE-2026-42058 [MEDIUM] CWE-732 CVE-2026-42058: An authenticated attacker's undisclosed requests to BIG-IP iControl REST can lead to an information An authenticated attacker's undisclosed requests to BIG-IP iControl REST can lead to an information leak of BIG-IP local user account names. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-20732P4MEDIUMCVSS 4.3≥ 16.1.0, ≤ 16.1.6≥ 17.1.0, < 17.1.3.1+1 more2026-02-04
CVE-2026-20732 [MEDIUM] CWE-451 CVE-2026-20732: A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacke A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2018-15325P4MEDIUMCVSS 4.3≥ 13.0.0, ≤ 13.1.1.1≥ 14.0.0, ≤ 14.0.0.22018-10-31
CVE-2018-15325 [MEDIUM] CWE-400 CVE-2018-15325: In BIG-IP 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1, iControl and TMSH usage by authenticated users may lea In BIG-IP 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1, iControl and TMSH usage by authenticated users may leak a small amount of memory when executing commands
nvd
CVE-2020-5905P4MEDIUMCVSS 4.3≥ 11.6.1, ≤ 11.6.5.22020-07-01
CVE-2020-5905 [MEDIUM] CWE-79 CVE-2020-5905: In version 11.6.1-11.6.5.2 of the BIG-IP system Configuration utility Network > WCCP page, the syste In version 11.6.1-11.6.5.2 of the BIG-IP system Configuration utility Network > WCCP page, the system does not sanitize all user-provided data before display.
nvd
CVE-2018-5540P4MEDIUMCVSS 4.4≥ 11.5.1, ≤ 11.5.6≥ 11.6.0, ≤ 11.6.3.1+2 more2018-07-19
CVE-2018-5540 [MEDIUM] CWE-732 CVE-2018-5540: On F5 BIG-IP 13.0.0-13.0.1, 12.1.0-12.1.3.3, 11.6.0-11.6.3.1, or 11.5.1-11.5.6, Enterprise Manager 3 On F5 BIG-IP 13.0.0-13.0.1, 12.1.0-12.1.3.3, 11.6.0-11.6.3.1, or 11.5.1-11.5.6, Enterprise Manager 3.1.1, BIG-IQ Centralized Management 5.0.0-5.1.0, BIG-IQ Cloud and Orchestration 1.0.0, or F5 iWorkflow 2.1.0-2.3.0 the big3d process does not irrevocably minimize group privileges at start up.
nvd
CVE-2019-6670P4MEDIUMCVSS 4.4≥ 11.5.1, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.5+4 more2019-11-27
CVE-2019-6670 [MEDIUM] CWE-312 CVE-2019-6670: On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.1-11 On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.1-11.6.5, vCMP hypervisors are incorrectly exposing the plaintext unit key for their vCMP guests on the filesystem.
nvd
CVE-2026-42408P4MEDIUMCVSS 4.4≥ 16.1.0, ≤ 16.1.6≥ 17.1.0, ≤ 17.1.3+1 more2026-05-13
CVE-2026-42408 [MEDIUM] CWE-312 CVE-2026-42408: When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed TMOS Shell (tmsh) command t When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed TMOS Shell (tmsh) command that may allow a highly privileged authenticated attacker to view sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2019-6635P4MEDIUMCVSS 4.4≥ 11.5.2, < 11.5.9≥ 11.6.1, < 11.6.4+4 more2019-07-03
CVE-2019-6635 [MEDIUM] CVE-2019-6635: On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11. On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.1-11.5.8, when the BIG-IP system is licensed for Appliance mode, a user with either the Administrator or the Resource Administrator role can bypass Appliance mode restrictions.
nvd
CVE-2019-6633P4MEDIUMCVSS 4.4≥ 11.5.2, ≤ 11.5.9≥ 11.6.1, ≤ 11.6.4+4 more2019-07-03
CVE-2019-6633 [MEDIUM] CVE-2019-6633: On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4.1, and 11.5.1-11.6.4, whe On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4.1, and 11.5.1-11.6.4, when the BIG-IP system is licensed with Appliance mode, user accounts with Administrator and Resource Administrator roles can bypass Appliance mode restrictions.
nvd
CVE-2022-1389P4MEDIUMCVSS 4.3v11.6.1v11.6.2+29 more2022-05-05
CVE-2022-1389 [MEDIUM] CWE-352 CVE-2022-1389: On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP (fixed in 17.0.0) On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP (fixed in 17.0.0), a cross-site request forgery (CSRF) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility. This vulnerability allows an attacker to run a limited set of commands: ping, traceroute, and WOM diagnostics. Note: Software versions
nvd
CVE-2020-5851P4MEDIUMCVSS 4.6v14.1.0.2.0.45.4v14.1.0.2.0.62.42020-01-14
CVE-2020-5851 [MEDIUM] CVE-2020-5851: On impacted versions and platforms the Trusted Platform Module (TPM) system integrity check cannot d On impacted versions and platforms the Trusted Platform Module (TPM) system integrity check cannot detect modifications to specific system components. This issue only impacts specific engineering hotfixes and platforms. NOTE: This vulnerability does not affect any of the BIG-IP major, minor or maintenance releases you obtained from downloads.f5.com. The affec
nvd
CVE-2023-45219P4MEDIUMCVSS 4.4≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, ≤ 14.1.5+2 more2023-10-10
CVE-2023-45219 [MEDIUM] CWE-200 CVE-2023-45219: Exposure of Sensitive Information vulnerability exist in an undisclosed BIG-IP TMOS shell (tmsh) co Exposure of Sensitive Information vulnerability exist in an undisclosed BIG-IP TMOS shell (tmsh) command which may allow an authenticated attacker with resource administrator role privileges to view sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2018-5538P4LOWCVSS 3.7≥ 12.1.3, ≤ 12.1.3.5≥ 13.1.0, ≤ 13.1.0.72018-07-25
CVE-2018-5538 [LOW] CVE-2018-5538: On F5 BIG-IP DNS 13.1.0-13.1.0.7, 12.1.3-12.1.3.5, DNS Express / DNS Zones accept NOTIFY messages on On F5 BIG-IP DNS 13.1.0-13.1.0.7, 12.1.3-12.1.3.5, DNS Express / DNS Zones accept NOTIFY messages on the management interface from source IP addresses not listed in the 'Allow NOTIFY From' configuration parameter when the db variable "dnsexpress.notifyport" is set to any value other than the default of "0".
nvd