cbcvebase.

F5 Big-Ip Local Traffic Manager vulnerabilities

535 known vulnerabilities affecting f5/big-ip_local_traffic_manager.

Total CVEs
535
CISA KEV
11
actively exploited
Public exploits
22
Exploited in wild
15
Severity breakdown
CRITICAL42HIGH299MEDIUM189LOW5

Vulnerabilities

Page 10 of 27
CVE-2018-5527P3HIGHCVSS 7.5≥ 13.0.0, ≤ 13.1.0.72018-06-27
CVE-2018-5527 [HIGH] CWE-772 CVE-2018-5527: On BIG-IP 13.1.0-13.1.0.7, a remote attacker using undisclosed methods against virtual servers confi On BIG-IP 13.1.0-13.1.0.7, a remote attacker using undisclosed methods against virtual servers configured with a Client SSL or Server SSL profile that has the SSL Forward Proxy feature enabled can force the Traffic Management Microkernel (tmm) to leak memory. As a result, system memory usage increases over time, which may eventually cause a decrease in
nvd
CVE-2019-6623P3HIGHCVSS 7.5≥ 12.1.0, ≤ 12.1.4≥ 13.0.0, ≤ 13.1.1.4+2 more2019-07-02
CVE-2019-6623 [HIGH] CVE-2019-6623: On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, and 12.1.0-12.1.4, undisclosed traffic On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, and 12.1.0-12.1.4, undisclosed traffic sent to BIG-IP iSession virtual server may cause the Traffic Management Microkernel (TMM) to restart, resulting in a Denial-of-Service (DoS).
nvd
CVE-2021-23012P3HIGHCVSS 8.2≥ 13.1.0, < 13.1.4≥ 14.1.0, < 14.1.4+2 more2021-05-10
CVE-2021-23012 [HIGH] CWE-78 CVE-2021-23012: On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, and 13.1.x be On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, and 13.1.x before 13.1.4, lack of input validation for items used in the system support functionality may allow users granted either "Resource Administrator" or "Administrator" roles to execute arbitrary bash commands on BIG-IP. Note: Software versions which have rea
nvd
CVE-2019-6603P3HIGHCVSS 7.5≥ 11.5.1, ≤ 11.5.8≥ 11.6.1, ≤ 11.6.3+2 more2019-03-28
CVE-2019-6603 [HIGH] CVE-2019-6603: In BIG-IP 11.5.1-11.5.8, 11.6.1-11.6.3, 12.1.0-12.1.3, and 13.0.0-13.0.1, malformed TCP packets sent In BIG-IP 11.5.1-11.5.8, 11.6.1-11.6.3, 12.1.0-12.1.3, and 13.0.0-13.0.1, malformed TCP packets sent to a self IP address or a FastL4 virtual server may cause an interruption of service. The control plane is not exposed to this issue. This issue impacts the data plane virtual servers and self IPs.
nvd
CVE-2016-6876P3HIGHCVSS 7.5v10.2.1v10.2.2+12 more2016-09-07
CVE-2016-6876 [HIGH] CWE-399 CVE-2016-6876: The RESOLV::lookup iRule command in F5 BIG-IP LTM, APM, ASM, and Link Controller 10.2.1 through 10.2 The RESOLV::lookup iRule command in F5 BIG-IP LTM, APM, ASM, and Link Controller 10.2.1 through 10.2.4, 11.2.1, 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.6.1, and 12.0.0 before HF3; BIG-IP AAM, AFM, and PEM 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.6.1, and 12.0.0 before HF3; BIG-IP Analytics 11.2.1, 11.4.x, 11.5.x before 11.5.4 HF2, 1
nvd
CVE-2018-5502P3HIGHCVSS 7.5≥ 13.0.0, < 13.1.0.42018-03-22
CVE-2018-5502 [HIGH] CWE-295 CVE-2018-5502: On F5 BIG-IP versions 13.0.0 - 13.1.0.3, attackers may be able to disrupt services on the BIG-IP sys On F5 BIG-IP versions 13.0.0 - 13.1.0.3, attackers may be able to disrupt services on the BIG-IP system with maliciously crafted client certificate. This vulnerability affects virtual servers associated with Client SSL profile which enables the use of client certificate authentication. Client certificate authentication is not enabled by default in Clien
nvd
CVE-2020-5881P3HIGHCVSS 7.5≥ 13.1.0, ≤ 13.1.3.3≥ 14.1.0, ≤ 14.1.2.3+1 more2020-04-30
CVE-2020-5881 [HIGH] CVE-2020-5881: On versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, and 13.1.0-13.1.3.3, when the BIG-IP Virtual Edition ( On versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, and 13.1.0-13.1.3.3, when the BIG-IP Virtual Edition (VE) is configured with VLAN groups and there are devices configured with OSPF connected to it, the Network Device Abstraction Layer (NDAL) Interfaces can lock up and in turn disrupting the communication between the mcpd and tmm processes.
nvd
CVE-2020-5852P3HIGHCVSS 7.5v11.5.4.2.74.291v12.1.4.1.0.97.6+1 more2020-01-14
CVE-2020-5852 [HIGH] CVE-2020-5852: Undisclosed traffic patterns received may cause a disruption of service to the Traffic Management Mi Undisclosed traffic patterns received may cause a disruption of service to the Traffic Management Microkernel (TMM). This vulnerability affects TMM through a virtual server configured with a FastL4 profile. Traffic processing is disrupted while TMM restarts. This issue only impacts specific engineering hotfixes. NOTE: This vulnerability does not affect any of t
nvd
CVE-2022-34862P3HIGHCVSS 7.5≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, < 14.1.5+2 more2022-08-04
CVE-2022-34862 [HIGH] CWE-835 CVE-2022-34862: In BIG-IP Versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all ver In BIG-IP Versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, when an LTM virtual server is configured to perform normalization, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not
nvd
CVE-2017-6167P3HIGHCVSS 7.5≥ 12.1.0, ≤ 12.1.2v13.0.02017-12-21
CVE-2017-6167 [HIGH] CWE-362 CVE-2017-6167: In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM and WebSafe software vers In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM and WebSafe software version 13.0.0 and 12.1.0 - 12.1.2, race conditions in iControl REST may lead to commands being executed with different privilege levels than expected.
nvd
CVE-2020-5918P3HIGHCVSS 7.5≥ 11.6.1, < 11.6.5.2≥ 12.1.0, < 12.1.5.2+4 more2020-08-26
CVE-2020-5918 [HIGH] CVE-2020-5918: In BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5 In BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management Microkernel (TMM) may stop responding when processing Stream Control Transmission Protocol (SCTP) traffic when traffic volume is high. This vulnerability affects TMM by way of a virtual server configured with an SCT
nvd
CVE-2019-6684P3HIGHCVSS 7.5≥ 11.5.2, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.5+3 more2019-12-23
CVE-2019-6684 [HIGH] CVE-2019-6684: On versions 15.0.0-15.0.1.1, 14.0.0-14.1.2.2, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, u On versions 15.0.0-15.0.1.1, 14.0.0-14.1.2.2, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, under certain conditions, a multi-bladed BIG-IP Virtual Clustered Multiprocessing (vCMP) may drop broadcast packets when they are rebroadcast to the vCMP guest secondary blades. An attacker can leverage the fragmented broadcast IP packets to perform any type of fr
nvd
CVE-2021-23011P3HIGHCVSS 7.5≥ 11.6.1, < 11.6.5.3≥ 12.1.0, < 12.1.6+4 more2021-05-10
CVE-2021-23011 [HIGH] CWE-400 CVE-2021-23011: On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before 13.1.4 On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before 13.1.4, 12.1.x before 12.1.6, and 11.6.x before 11.6.5.3, when the BIG-IP system is buffering packet fragments for reassembly, the Traffic Management Microkernel (TMM) may consume an excessive amount of resources, eventually leading to a restart and failover
nvd
CVE-2021-23004P3HIGHCVSS 7.5≥ 11.6.1, < 11.6.5.3≥ 12.1.0, < 12.1.5.3+4 more2021-03-31
CVE-2021-23004 [HIGH] CVE-2021-23004: On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x befo On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, Multipath TCP (MPTCP) forwarding flows may be created on standard virtual servers without MPTCP enabled in the applied TCP profile. Note: Software versions which have reached End of Software Devel
nvd
CVE-2021-23044P3HIGHCVSS 7.5≥ 11.6.0, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.6+4 more2021-09-14
CVE-2021-23044 [HIGH] CWE-20 CVE-2021-23044: On BIG-IP version 16.x before 16.1.0, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, 13.1.x before On BIG-IP version 16.x before 16.1.0, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x and 11.6.x, when the Intel QuickAssist Technology (QAT) compression driver is used on affected BIG-IP hardware and BIG-IP Virtual Edition (VE) platforms, undisclosed traffic can cause the Traffic Management Microkernel
nvd
CVE-2021-23045P3HIGHCVSS 7.5≥ 12.1.0, ≤ 12.1.6≥ 13.1.0, < 13.1.4.1+3 more2021-09-14
CVE-2021-23045 [HIGH] CWE-20 CVE-2021-23045: On BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, 13.1.x bef On BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, 13.1.x before 13.1.4.1, and all versions of 12.1.x, when an SCTP profile with multiple paths is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of
nvd
CVE-2021-23000P3HIGHCVSS 7.5≥ 13.1.3.4, < 13.1.3.6v12.1.5.22021-03-31
CVE-2021-23000 [HIGH] CVE-2021-23000: On BIG-IP versions 13.1.3.4-13.1.3.6 and 12.1.5.2, if the tmm.http.rfc.enforcement BigDB key is enab On BIG-IP versions 13.1.3.4-13.1.3.6 and 12.1.5.2, if the tmm.http.rfc.enforcement BigDB key is enabled in a BIG-IP system, or the Bad host header value is checked in the AFM HTTP security profile associated with a virtual server, in rare instances, a specific sequence of malicious requests may cause TMM to restart. Note: Software versions which have reached
nvd
CVE-2022-23012P3HIGHCVSS 7.5≥ 14.1.0, < 14.1.4.5≥ 15.1.0, < 15.1.4.12022-01-25
CVE-2022-23012 [HIGH] CWE-415 CVE-2022-23012: On BIG-IP versions 15.1.x before 15.1.4.1 and 14.1.x before 14.1.4.5, when the HTTP/2 profile is con On BIG-IP versions 15.1.x before 15.1.4.1 and 14.1.x before 14.1.4.5, when the HTTP/2 profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2022-23019P3HIGHCVSS 7.5≥ 12.1.0, ≤ 12.1.6≥ 13.1.0, ≤ 13.1.4+3 more2022-01-25
CVE-2022-23019 [HIGH] CWE-20 CVE-2022-23019: On BIG-IP version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.4, and all vers On BIG-IP version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x and 12.1.x, when a message routing type virtual server is configured with both Diameter Session and Router Profiles, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End o
nvd
CVE-2022-23022P3HIGHCVSS 7.5≥ 16.1.0, < 16.1.22022-01-25
CVE-2022-23022 [HIGH] CWE-476 CVE-2022-23022: On BIG-IP version 16.1.x before 16.1.2, when an HTTP profile is configured on a virtual server, undi On BIG-IP version 16.1.x before 16.1.2, when an HTTP profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
F5 Big-Ip Local Traffic Manager vulnerabilities | cvebase