F5 Big-Ip Policy Enforcement Manager vulnerabilities
527 known vulnerabilities affecting f5/big-ip_policy_enforcement_manager.
Total CVEs
527
CISA KEV
11
actively exploited
Public exploits
19
Exploited in wild
15
Severity breakdown
CRITICAL40HIGH293MEDIUM190LOW4
Vulnerabilities
Page 7 of 27
CVE-2019-6685P3HIGHCVSS 7.8≥ 11.5.2, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.5+4 more2019-12-23
CVE-2019-6685 [HIGH] CWE-269 CVE-2019-6685: On BIG-IP versions 15.0.0-15.0.1.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5,
On BIG-IP versions 15.0.0-15.0.1.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, users with access to edit iRules are able to create iRules which can lead to an elevation of privilege, configuration modification, and arbitrary system command execution.
nvd
CVE-2019-6620P3HIGHCVSS 7.2≥ 11.5.2, ≤ 11.6.4≥ 12.1.0, ≤ 12.1.4+2 more2019-07-02
CVE-2019-6620 [HIGH] CWE-78 CVE-2019-6620: On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.5, 13.0.0-13.1.1.4, 12.1.0-12.1.4.1, and 11.5.1-11.6.4 and
On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.5, 13.0.0-13.1.1.4, 12.1.0-12.1.4.1, and 11.5.1-11.6.4 and BIG-IQ 6.0.0-6.1.0 and 5.1.0-5.4.0, an undisclosed iControl REST worker vulnerable to command injection for an Administrator user.
nvd
CVE-2021-23039P3HIGHCVSS 7.5≥ 12.1.0, ≤ 12.1.6≥ 13.1.0, ≤ 13.1.4+3 more2021-09-14
CVE-2021-23039 [HIGH] CWE-20 CVE-2021-23039: On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.2.8, and all versions of
On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.2.8, and all versions of 13.1.x and 12.1.x, when IPSec is configured on a BIG-IP system, undisclosed requests from an authorized remote (IPSec) peer, which already has a negotiated Security Association, can cause the Traffic Management Microkernel (TMM) to terminate. Note: Soft
nvd
CVE-2021-23042P3HIGHCVSS 7.5≥ 12.1.0, < 12.1.6≥ 13.1.0, < 13.1.4+3 more2021-09-14
CVE-2021-23042 [HIGH] CWE-400 CVE-2021-23042: On BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before
On BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before 13.1.4, and 12.1.x before 12.1.6, when an HTTP profile is configured on a virtual server, undisclosed requests can cause a significant increase in system resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are
nvd
CVE-2022-34844P3HIGHCVSS 7.5≥ 15.1.0, < 15.1.6.1≥ 16.1.0, < 16.1.3.12022-08-04
CVE-2022-34844 [HIGH] CWE-20 CVE-2022-34844: In BIG-IP Versions 16.1.x before 16.1.3.1 and 15.1.x before 15.1.6.1, and all versions of BIG-IQ 8.x
In BIG-IP Versions 16.1.x before 16.1.3.1 and 15.1.x before 15.1.6.1, and all versions of BIG-IQ 8.x, when the Data Plane Development Kit (DPDK)/Elastic Network Adapter (ENA) driver is used with BIG-IP or BIG-IQ on Amazon Web Services (AWS) systems, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Successful exploita
nvd
CVE-2022-41833P3HIGHCVSS 7.5≥ 13.1.0, ≤ 13.1.52022-10-19
CVE-2022-41833 [HIGH] CWE-400 CVE-2022-41833: In all BIG-IP 13.1.x versions, when an iRule containing the HTTP::collect command is configured on a
In all BIG-IP 13.1.x versions, when an iRule containing the HTTP::collect command is configured on a virtual server, undisclosed requests can cause Traffic Management Microkernel (TMM) to terminate.
nvd
CVE-2024-23982P3HIGHCVSS 7.5≥ 15.1.0, ≤ 15.1.10≥ 16.1.0, ≤ 16.1.4+1 more2024-02-14
CVE-2024-23982 [HIGH] CWE-121 CVE-2024-23982: When a BIG-IP PEM classification profile is configured on a UDP virtual server, undisclosed reque
When a BIG-IP PEM classification profile is configured on a UDP virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. This issue affects classification engines using signatures released between 09-08-2022 and 02-16-2023. See the table in the F5 Security Advisory for a complete list of affected classificatio
nvd
CVE-2025-22891P3HIGHCVSS 7.5≥ 15.1.0, < 15.1.10.6.0.11.6≥ 16.1.0, < 16.1.5+1 more2025-02-05
CVE-2025-22891 [HIGH] CWE-772 CVE-2025-22891: When BIG-IP PEM Control Plane listener Virtual Server is configured with Diameter Endpoint profile,
When BIG-IP PEM Control Plane listener Virtual Server is configured with Diameter Endpoint profile, undisclosed traffic can cause the Virtual Server to stop processing new client connections and an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2025-35995P3HIGHCVSS 7.5≥ 15.1.0, < 15.1.10.7.0.4.5≥ 16.1.0, < 16.1.6+1 more2025-05-07
CVE-2025-35995 [HIGH] CWE-125 CVE-2025-35995: When a BIG-IP PEM system is licensed with URL categorization, and the URL categorization policy or a
When a BIG-IP PEM system is licensed with URL categorization, and the URL categorization policy or an iRule with the urlcat command is enabled on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2025-58071P3HIGHCVSS 7.5≥ 15.1.0, < 15.1.10.8≥ 16.1.0, < 16.1.6.1+2 more2025-10-15
CVE-2025-58071 [HIGH] CWE-457 CVE-2025-58071: When IPsec is configured on the BIG-IP system, undisclosed traffic can cause the Traffic Management
When IPsec is configured on the BIG-IP system, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2025-54479P3HIGHCVSS 7.5≥ 15.1.0, < 15.1.10.8≥ 16.1.0, < 16.1.6.1+2 more2025-10-15
CVE-2025-54479 [HIGH] CWE-787 CVE-2025-54479: When a classification profile is configured on a virtual server without an HTTP or HTTP/2 profile, u
When a classification profile is configured on a virtual server without an HTTP or HTTP/2 profile, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-40629P3HIGHCVSS 7.5≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+1 more2026-05-13
CVE-2026-40629 [HIGH] CWE-770 CVE-2026-40629: When SSL profiles are configured on a virtual server, undisclosed traffic can cause the virtual serv
When SSL profiles are configured on a virtual server, undisclosed traffic can cause the virtual server to stop processing new client connections. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-40618P3HIGHCVSS 7.5≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+2 more2026-05-13
CVE-2026-40618 [HIGH] CWE-131 CVE-2026-40618: When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel Q
When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel QuickAssist Technology (QAT) or on BIG-IP hardware platforms with the database variable crypto.hwacceleration set to disabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.
Note: Software versions which have reache
nvd
CVE-2026-40423P3HIGHCVSS 7.5≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+2 more2026-05-13
CVE-2026-40423 [HIGH] CWE-770 CVE-2026-40423: When a SIP profile is configured on a virtual server, undisclosed traffic can cause the Traffic Mana
When a SIP profile is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2021-23037P3CRITICALCVSS 9.6≥ 11.6.0, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.6+4 more2021-09-14
CVE-2021-23037 [CRITICAL] CWE-79 CVE-2021-23037: On all versions of 16.1.x, 16.0.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x, a reflected cross-sit
On all versions of 16.1.x, 16.0.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x, a reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to execute JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technica
nvd
CVE-2015-4047P3HIGHCVSS 7.8≥ 11.3.0, ≤ 11.6.4≥ 12.0.0, ≤ 12.1.4+1 more2015-05-29
CVE-2015-4047 [HIGH] CWE-476 CVE-2015-4047: racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL poin
racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a series of crafted UDP requests.
nvd
CVE-2022-28716P3HIGHCVSS 8.8≥ 11.6.1, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.6+4 more2022-05-05
CVE-2022-28716 [HIGH] CWE-79 CVE-2022-28716: On 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14
On 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x 11.6.x, a DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP AFM, CGNAT, and PEM Configuration utility that allows an attacker to execute Java
nvd
CVE-2020-5922P3HIGHCVSS 8.8≥ 11.6.1, ≤ 11.6.5≥ 12.1.0, < 12.1.5.2+3 more2020-08-26
CVE-2020-5922 [HIGH] CWE-352 CVE-2020-5922: In BIG-IP versions 15.0.0-15.1.0.4, 14.1.0-14.1.2.6, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11
In BIG-IP versions 15.0.0-15.1.0.4, 14.1.0-14.1.2.6, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2, iControl REST does not implement Cross Site Request Forgery protections for users which make use of Basic Authentication in a web browser.
nvd
CVE-2016-5736P3HIGHCVSS 7.5v11.4.0v11.4.1+7 more2016-08-19
CVE-2016-5736 [HIGH] CWE-284 CVE-2016-5736: The default configuration of the IPsec IKE peer listener in F5 BIG-IP LTM, Analytics, APM, ASM, and
The default configuration of the IPsec IKE peer listener in F5 BIG-IP LTM, Analytics, APM, ASM, and Link Controller 11.2.1 before HF16, 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.6.1, and 12.x before 12.0.0 HF2; BIG-IP AAM, AFM, and PEM 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.6.1, and 12.x before 12.0.0 HF2; BIG-IP DNS 12.x before 12.0
nvd
CVE-2020-5888P3HIGHCVSS 8.1≥ 14.0.0, < 14.1.2.4≥ 15.0.0, < 15.0.1.3+1 more2020-04-30
CVE-2020-5888 [HIGH] CVE-2020-5888: On versions 15.1.0-15.1.0.1, 15.0.0-15.0.1.2, and 14.1.0-14.1.2.3, BIG-IP Virtual Edition (VE) may e
On versions 15.1.0-15.1.0.1, 15.0.0-15.0.1.2, and 14.1.0-14.1.2.3, BIG-IP Virtual Edition (VE) may expose a mechanism for adjacent network (layer 2) attackers to access local daemons and bypass port lockdown settings.
nvd