F5 Big-Ip Next Cloud-Native Network Functions vulnerabilities
26 known vulnerabilities affecting f5/big-ip_next_cloud-native_network_functions.
Total CVEs
26
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH22MEDIUM4
Vulnerabilities
Page 2 of 2
CVE-2025-54805P3MEDIUMCVSS 6.5≥ 1.1.0, ≤ 1.4.12025-10-15
CVE-2025-54805 [MEDIUM] CWE-401 CVE-2025-54805: When an iRule is configured on a virtual server via the declarative API, upon re-instantiation, the
When an iRule is configured on a virtual server via the declarative API, upon re-instantiation, the cleanup process can cause an increase in the Traffic Management Microkernel (TMM) memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-45886P3HIGHCVSS 7.5≥ 1.1.0, ≤ 1.1.12023-11-21
CVE-2023-45886 [HIGH] CVE-2023-45886: The BGP daemon (bgpd) in IP Infusion ZebOS through 7.10.6 allow remote attackers to cause a denial o
The BGP daemon (bgpd) in IP Infusion ZebOS through 7.10.6 allow remote attackers to cause a denial of service by sending crafted BGP update messages containing a malformed attribute.
nvd
CVE-2025-55670P3MEDIUMCVSS 6.5≥ 1.1.0, ≤ 1.4.12025-10-15
CVE-2025-55670 [MEDIUM] CWE-770 CVE-2025-55670: On BIG-IP Next CNF, BIG-IP Next SPK, and BIG-IP Next for Kubernetes systems, repeated undisclosed AP
On BIG-IP Next CNF, BIG-IP Next SPK, and BIG-IP Next for Kubernetes systems, repeated undisclosed API calls can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2024-23306P4HIGHCVSS 7.1≥ 1.1.0, < 1.2.02024-02-14
CVE-2024-23306 [HIGH] CWE-522 CVE-2024-23306: A vulnerability exists in BIG-IP Next CNF and SPK systems that may allow access to undisclosed sensi
A vulnerability exists in BIG-IP Next CNF and SPK systems that may allow access to undisclosed sensitive files. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
CVE-2025-54500P4MEDIUMCVSS 5.3≥ 1.1.0, ≤ 1.4.1≥ 2.0.0, ≤ 2.0.22025-08-13
CVE-2025-54500 [MEDIUM] CWE-770 CVE-2025-54500: An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control fr
An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit (HTTP/2 MadeYouReset Attack).
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2024-28132P4MEDIUMCVSS 4.4≥ 1.2.0, < 1.3.02024-05-08
CVE-2024-28132 [MEDIUM] CWE-922 CVE-2024-28132: Exposure of Sensitive Information vulnerability exists in the GSLB container, which may allow an au
Exposure of Sensitive Information vulnerability exists in the GSLB container, which may allow an authenticated attacker with local access to view sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
← Previous2 / 2