cbcvebase.

F5 Big-Ip Policy Enforcement Manager vulnerabilities

527 known vulnerabilities affecting f5/big-ip_policy_enforcement_manager.

Total CVEs
527
CISA KEV
11
actively exploited
Public exploits
19
Exploited in wild
15
Severity breakdown
CRITICAL40HIGH293MEDIUM190LOW4

Vulnerabilities

Page 17 of 27
CVE-2019-12295P3HIGHCVSS 7.5≥ 12.1.3.6, < 12.1.5.3≥ 13.1.1.2, < 13.1.3.5+4 more2019-05-23
CVE-2019-12295 [HIGH] CWE-674 CVE-2019-12295: In Wireshark 3.0.0 to 3.0.1, 2.6.0 to 2.6.8, and 2.4.0 to 2.4.14, the dissection engine could crash. In Wireshark 3.0.0 to 3.0.1, 2.6.0 to 2.6.8, and 2.4.0 to 2.4.14, the dissection engine could crash. This was addressed in epan/packet.c by restricting the number of layers and consequently limiting recursion.
nvd
CVE-2026-40462P3MEDIUMCVSS 6.5≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+2 more2026-05-13
CVE-2026-40462 [MEDIUM] CWE-732 CVE-2026-40462: Incorrect permission assignment vulnerabilities exist in iControl REST and TMOS shell (tmsh) undiscl Incorrect permission assignment vulnerabilities exist in iControl REST and TMOS shell (tmsh) undisclosed command which may allow an authenticated attacker to view sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2020-5945P3HIGHCVSS 8.4≥ 14.1.0, < 14.1.2.8≥ 15.1.0, < 15.1.1+1 more2020-11-05
CVE-2020-5945 [HIGH] CWE-79 CVE-2020-5945: In BIG-IP versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.2.7, undisclosed TMUI page cont In BIG-IP versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.2.7, undisclosed TMUI page contains a stored cross site scripting vulnerability (XSS). The issue allows a minor privilege escalation for resource admin to escalate to full admin.
nvd
CVE-2013-3587P3MEDIUMCVSS 5.9≥ 11.3.0, ≤ 11.6.1≥ 12.0.0, ≤ 12.1.2+1 more2020-02-21
CVE-2013-3587 [MEDIUM] CVE-2013-3587: The HTTPS protocol, as used in unspecified web applications, can encrypt compressed data without pro The HTTPS protocol, as used in unspecified web applications, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which makes it easier for man-in-the-middle attackers to obtain plaintext secret values by observing length differences during a series of guesses in which a string in an HTTP request URL potentially matches
nvd
CVE-2016-9249P3HIGHCVSS 7.5v12.0.0v12.1.0+1 more2017-01-31
CVE-2016-9249 [HIGH] CWE-20 CVE-2016-9249: An undisclosed traffic pattern received by a BIG-IP Virtual Server with TCP Fast Open enabled may ca An undisclosed traffic pattern received by a BIG-IP Virtual Server with TCP Fast Open enabled may cause the Traffic Management Microkernel (TMM) to restart, resulting in a Denial-of-Service (DoS).
nvd
CVE-2016-9252P3HIGHCVSS 7.5v11.4.0v11.4.1+10 more2017-03-27
CVE-2016-9252 [HIGH] CWE-19 CVE-2016-9252: The Traffic Management Microkernel (TMM) in F5 BIG-IP before 11.5.4 HF3, 11.6.x before 11.6.1 HF2 an The Traffic Management Microkernel (TMM) in F5 BIG-IP before 11.5.4 HF3, 11.6.x before 11.6.1 HF2 and 12.x before 12.1.2 does not properly handle minimum path MTU options for IPv6, which allows remote attackers to cause a denial-of-service (DoS) through unspecified vectors.
nvd
CVE-2025-24320P3HIGHCVSS 8.0≥ 15.1.0, < 15.1.10.6≥ 16.1.0, < 16.1.5.2+1 more2025-02-05
CVE-2025-24320 [HIGH] CVE-2025-24320: A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Config A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. This vulnerability is due to an incomplete fix for CVE-2024-31156 https://my.f5.com/manage/s/article/K000138636 . Note: Software versions which have reach
nvd
CVE-2017-6128P3HIGHCVSS 7.5v11.4.0v11.4.1+7 more2017-05-01
CVE-2017-6128 [HIGH] CVE-2017-6128: An attacker may be able to cause a denial-of-service (DoS) attack against the sshd component in F5 B An attacker may be able to cause a denial-of-service (DoS) attack against the sshd component in F5 BIG-IP, Enterprise Manager, BIG-IQ, and iWorkflow.
nvd
CVE-2019-6628P3HIGHCVSS 7.5≥ 14.0.0, ≤ 14.0.0.4≥ 14.1.0, ≤ 14.1.0.52019-07-03
CVE-2019-6628 [HIGH] CVE-2019-6628: On BIG-IP PEM 14.1.0-14.1.0.5 and 14.0.0-14.0.0.4, under certain conditions, the TMM process may ter On BIG-IP PEM 14.1.0-14.1.0.5 and 14.0.0-14.0.0.4, under certain conditions, the TMM process may terminate and restart while processing BIG-IP PEM traffic with the OpenVPN classifier.
nvd
CVE-2020-5875P3HIGHCVSS 7.5≥ 14.1.0, ≤ 14.1.2.3≥ 15.0.0, ≤ 15.0.12020-04-30
CVE-2020-5875 [HIGH] CVE-2020-5875: On BIG-IP 15.0.0-15.0.1 and 14.1.0-14.1.2.3, under certain conditions, the Traffic Management Microk On BIG-IP 15.0.0-15.0.1 and 14.1.0-14.1.2.3, under certain conditions, the Traffic Management Microkernel (TMM) may generate a core file and restart while processing SSL traffic with an HTTP/2 full proxy.
nvd
CVE-2020-5862P3HIGHCVSS 7.5≥ 14.1.0, ≤ 14.1.2≥ 15.0.0, ≤ 15.0.1.1+1 more2020-03-27
CVE-2020-5862 [HIGH] CWE-20 CVE-2020-5862: On BIG-IP 15.1.0-15.1.0.1, 15.0.0-15.0.1.1, and 14.1.0-14.1.2.2, under certain conditions, TMM may c On BIG-IP 15.1.0-15.1.0.1, 15.0.0-15.0.1.1, and 14.1.0-14.1.2.2, under certain conditions, TMM may crash or stop processing new traffic with the DPDK/ENA driver on AWS systems while sending traffic. This issue does not affect any other platforms, hardware or virtual, or any other cloud provider since the affected driver is specific to AWS.
nvd
CVE-2020-5871P3HIGHCVSS 7.5≥ 14.1.0, ≤ 14.1.2.32020-04-30
CVE-2020-5871 [HIGH] CVE-2020-5871: On BIG-IP 14.1.0-14.1.2.3, undisclosed requests can lead to a denial of service (DoS) when sent to B On BIG-IP 14.1.0-14.1.2.3, undisclosed requests can lead to a denial of service (DoS) when sent to BIG-IP HTTP/2 virtual servers. The problem can occur when ciphers, which have been blacklisted by the HTTP/2 RFC, are used on backend servers. This is a data-plane issue. There is no control-plane exposure.
nvd
CVE-2020-5878P3HIGHCVSS 7.5≥ 14.1.0, ≤ 14.1.2.3≥ 15.0.0, ≤ 15.0.1.1+1 more2020-04-30
CVE-2020-5878 [HIGH] CVE-2020-5878: On versions 15.1.0-15.1.0.1, 15.0.0-15.0.1.1, and 14.1.0-14.1.2.3, Traffic Management Microkernel (T On versions 15.1.0-15.1.0.1, 15.0.0-15.0.1.1, and 14.1.0-14.1.2.3, Traffic Management Microkernel (TMM) may restart on BIG-IP Virtual Edition (VE) while processing unusual IP traffic.
nvd
CVE-2020-5857P3HIGHCVSS 7.5≥ 11.5.2, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.5+3 more2020-03-27
CVE-2020-5857 [HIGH] CVE-2020-5857: On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2.2, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, undis On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2.2, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, undisclosed HTTP behavior may lead to a denial of service.
nvd
CVE-2020-5856P3HIGHCVSS 7.5≥ 14.1.0, < 14.1.2.3≥ 15.0.0, < 15.1.02020-02-06
CVE-2020-5856 [HIGH] CVE-2020-5856: On BIG-IP 15.0.0-15.0.1.1 and 14.1.0-14.1.2.2, while processing specifically crafted traffic using t On BIG-IP 15.0.0-15.0.1.1 and 14.1.0-14.1.2.2, while processing specifically crafted traffic using the default 'xnet' driver, Virtual Edition instances hosted in Amazon Web Services (AWS) may experience a TMM restart.
nvd
CVE-2019-6671P3HIGHCVSS 7.5≥ 13.1.0, ≤ 13.1.3.1≥ 14.0.0, ≤ 14.0.1+2 more2019-11-27
CVE-2019-6671 [HIGH] CWE-401 CVE-2019-6671: On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, and 13.1.0-13.1.3.1, under certain conditions On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, and 13.1.0-13.1.3.1, under certain conditions tmm may leak memory when processing packet fragments, leading to resource starvation.
nvd
CVE-2019-6669P3HIGHCVSS 7.5≥ 11.5.1, ≤ 11.6.5.1≥ 12.1.0, ≤ 12.1.5+4 more2019-11-27
CVE-2019-6669 [HIGH] CVE-2019-6669: On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.1-11 On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.1-11.6.5.1, undisclosed traffic flow may cause TMM to restart under some circumstances.
nvd
CVE-2019-6614P3MEDIUMCVSS 6.5≥ 12.1.0, < 12.1.4.1≥ 13.0.0, < 13.1.1.5+1 more2019-05-03
CVE-2019-6614 [MEDIUM] CVE-2019-6614: On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, and 12.1.0-12.1.4, internal methods used to prevent arbi On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, and 12.1.0-12.1.4, internal methods used to prevent arbitrary file overwrites in Appliance Mode were not fully effective. An authenticated attacker with a high privilege level may be able to bypass protections implemented in appliance mode to overwrite arbitrary system files.
nvd
CVE-2022-23023P3MEDIUMCVSS 6.5≥ 12.1.0, ≤ 12.1.5≥ 13.1.0, ≤ 13.1.4+3 more2022-01-25
CVE-2022-23023 [MEDIUM] CWE-400 CVE-2022-23023: On BIG-IP version 16.1.x before 16.1.2.1, 15.1.x before 15.1.5, 14.1.x before 14.1.4.5, and all vers On BIG-IP version 16.1.x before 16.1.2.1, 15.1.x before 15.1.5, 14.1.x before 14.1.4.5, and all versions of 13.1.x and 12.1.x, and BIG-IQ all versions of 8.x and 7.x, undisclosed requests by an authenticated iControl REST user can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (E
nvd
CVE-2024-21782P3MEDIUMCVSS 6.7≥ 15.1.0, < 15.1.9≥ 16.1.0, < 16.1.4+1 more2024-02-14
CVE-2024-21782 [MEDIUM] CVE-2024-21782: BIG-IP or BIG-IQ Resource Administrators and Certificate Managers who have access to the secure copy BIG-IP or BIG-IQ Resource Administrators and Certificate Managers who have access to the secure copy (scp) utility but do not have access to Advanced shell (bash) can execute arbitrary commands with a specially crafted command string. This vulnerability is due to an incomplete fix for CVE-2020-5873. Note: Software versions which have reached End of Techni
nvd