F5 Big-Ip Next Cnf vulnerabilities
26 known vulnerabilities affecting f5/big-ip_next_cnf.
Total CVEs
26
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH22MEDIUM4
Vulnerabilities
Page 2 of 2
CVE-2024-25560P3HIGHCVSS 7.5≥ 1.1.0, < 1.2.02024-05-08
CVE-2024-25560 [HIGH] CWE-476 CVE-2024-25560: When BIG-IP AFM is licensed and provisioned, undisclosed DNS traffic can cause the Traffic Manageme
When BIG-IP AFM is licensed and provisioned, undisclosed DNS traffic can cause the Traffic Management Microkernel (TMM) to terminate.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2025-54805P3MEDIUMCVSS 6.5≥ 1.1.0, < *2025-10-15
CVE-2025-54805 [MEDIUM] CWE-401 CVE-2025-54805: When an iRule is configured on a virtual server via the declarative API, upon re-instantiation, the
When an iRule is configured on a virtual server via the declarative API, upon re-instantiation, the cleanup process can cause an increase in the Traffic Management Microkernel (TMM) memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2025-55670P3MEDIUMCVSS 6.5≥ 1.1.0, < *2025-10-15
CVE-2025-55670 [MEDIUM] CWE-770 CVE-2025-55670: On BIG-IP Next CNF, BIG-IP Next SPK, and BIG-IP Next for Kubernetes systems, repeated undisclosed AP
On BIG-IP Next CNF, BIG-IP Next SPK, and BIG-IP Next for Kubernetes systems, repeated undisclosed API calls can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2024-23306P4HIGHCVSS 7.1≥ 1.0.0, < 1.2.02024-02-14
CVE-2024-23306 [HIGH] CWE-522 CVE-2024-23306: A vulnerability exists in BIG-IP Next CNF and SPK systems that may allow access to undisclosed sensi
A vulnerability exists in BIG-IP Next CNF and SPK systems that may allow access to undisclosed sensitive files. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
CVE-2025-54500P4MEDIUMCVSS 5.3≥ 2.0.0, < *≥ 1.1.0, < *2025-08-13
CVE-2025-54500 [MEDIUM] CWE-770 CVE-2025-54500: An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control fr
An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit (HTTP/2 MadeYouReset Attack).
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2024-28132P4MEDIUMCVSS 4.4≥ 1.2.0, < 1.3.02024-05-08
CVE-2024-28132 [MEDIUM] CWE-922 CVE-2024-28132: Exposure of Sensitive Information vulnerability exists in the GSLB container, which may allow an au
Exposure of Sensitive Information vulnerability exists in the GSLB container, which may allow an authenticated attacker with local access to view sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
← Previous2 / 2