F5 Big-Ip Policy Enforcement Manager vulnerabilities
527 known vulnerabilities affecting f5/big-ip_policy_enforcement_manager.
Total CVEs
527
CISA KEV
11
actively exploited
Public exploits
19
Exploited in wild
15
Severity breakdown
CRITICAL40HIGH293MEDIUM190LOW4
Vulnerabilities
Page 8 of 27
CVE-2021-23034P3HIGHCVSS 7.5≥ 15.1.0, < 15.1.3.1≥ 16.0.0, < 16.1.02021-09-14
CVE-2021-23034 [HIGH] CWE-20 CVE-2021-23034: On BIG-IP version 16.x before 16.1.0 and 15.1.x before 15.1.3.1, when a DNS profile using a DNS cach
On BIG-IP version 16.x before 16.1.0 and 15.1.x before 15.1.3.1, when a DNS profile using a DNS cache resolver is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2022-23017P3HIGHCVSS 7.5≥ 13.1.0, ≤ 13.1.4≥ 14.1.0, < 14.1.4.5+2 more2022-01-25
CVE-2022-23017 [HIGH] CWE-476 CVE-2022-23017: On BIG-IP version 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versio
On BIG-IP version 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versions of 13.1.x, when a virtual server is configured with a DNS profile with the Rapid Response Mode setting enabled and is configured on a BIG-IP system, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software
nvd
CVE-2022-27189P3HIGHCVSS 7.5v11.6.1v11.6.2+29 more2022-05-05
CVE-2022-27189 [HIGH] CWE-681 CVE-2022-27189: On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions p
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, when an Internet Content Adaptation Protocol (ICAP) profile is configured on a virtual server, undisclosed traffic can cause an increase in Traffic Management Micr
nvd
CVE-2022-34655P3HIGHCVSS 7.5≥ 14.1.0, < 14.1.5≥ 15.1.0, < 15.1.6.1+1 more2022-08-04
CVE-2022-34655 [HIGH] CWE-457 CVE-2022-34655: In BIG-IP Versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when an
In BIG-IP Versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when an iRule containing the HTTP::payload command is configured on a virtual server, undisclosed traffic can cause Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2022-34651P3HIGHCVSS 7.5≥ 15.1.0, < 15.1.6.1≥ 16.1.0, < 16.1.3.12022-08-04
CVE-2022-34651 [HIGH] CWE-476 CVE-2022-34651: In BIG-IP Versions 16.1.x before 16.1.3.1 and 15.1.x before 15.1.6.1, when an LTM Client or Server S
In BIG-IP Versions 16.1.x before 16.1.3.1 and 15.1.x before 15.1.6.1, when an LTM Client or Server SSL profile with TLS 1.3 enabled is configured on a virtual server, along with an iRule that calls HTTP::respond, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Tech
nvd
CVE-2023-22422P3HIGHCVSS 7.5≥ 16.1.0, < 16.1.3.3≥ 17.0.0, < 17.0.0.22023-02-01
CVE-2023-22422 [HIGH] CWE-120 CVE-2023-22422: On BIG-IP versions 17.0.x before 17.0.0.2 and 16.1.x before 16.1.3.3, when a HTTP profile with the n
On BIG-IP versions 17.0.x before 17.0.0.2 and 16.1.x before 16.1.3.3, when a HTTP profile with the non-default Enforcement options of Enforce HTTP Compliance and Unknown Methods: Reject are configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached En
nvd
CVE-2021-23015P3HIGHCVSS 7.2≥ 13.1.0, < 13.1.4≥ 14.1.0, < 14.1.4+2 more2021-05-10
CVE-2021-23015 [HIGH] CWE-863 CVE-2021-23015: On BIG-IP 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.0.8 through 13.1.3.6, and all versions
On BIG-IP 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.0.8 through 13.1.3.6, and all versions of 16.0.x, when running in Appliance Mode, an authenticated user assigned the 'Administrator' role may be able to bypass Appliance Mode restrictions utilizing undisclosed iControl REST endpoints. Note: Software versions which have reached End of Technica
nvd
CVE-2024-23314P3HIGHCVSS 7.5≥ 15.1.0, < 15.1.9≥ 16.1.0, < 16.1.4+1 more2024-02-14
CVE-2024-23314 [HIGH] CWE-908 CVE-2024-23314: When HTTP/2 is configured on BIG-IP or BIG-IP Next SPK systems, undisclosed responses can cause the
When HTTP/2 is configured on BIG-IP or BIG-IP Next SPK systems, undisclosed responses can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
CVE-2022-32455P3HIGHCVSS 7.5≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, < 14.1.5+2 more2022-08-04
CVE-2022-32455 [HIGH] CWE-119 CVE-2022-32455: In BIG-IP Versions 16.1.x before 16.1.2.2, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all ver
In BIG-IP Versions 16.1.x before 16.1.2.2, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, when a BIG-IP LTM Client SSL profile is configured on a virtual server to perform client certificate authentication with session tickets enabled, undisclosed requests cause the Traffic Management Microkernel (TMM) to terminate. Note: So
nvd
CVE-2024-41164P3HIGHCVSS 7.5≥ 15.1.0, ≤ 15.1.1≥ 16.1.0, < 16.1.5+1 more2024-08-14
CVE-2024-41164 [HIGH] CWE-476 CVE-2024-41164: When TCP profile with Multipath TCP enabled (MPTCP) is configured on a Virtual Server, undisclosed t
When TCP profile with Multipath TCP enabled (MPTCP) is configured on a Virtual Server, undisclosed traffic along with conditions beyond the attackers control can cause TMM to terminate.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2025-35995P3HIGHCVSS 7.5≥ 15.1.0, < 15.1.10.7.0.4.5≥ 16.1.0, < 16.1.6+1 more2025-05-07
CVE-2025-35995 [HIGH] CWE-125 CVE-2025-35995: When a BIG-IP PEM system is licensed with URL categorization, and the URL categorization policy or a
When a BIG-IP PEM system is licensed with URL categorization, and the URL categorization policy or an iRule with the urlcat command is enabled on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2025-41431P3HIGHCVSS 7.5v17.1.22025-05-07
CVE-2025-41431 [HIGH] CWE-787 CVE-2025-41431: When connection mirroring is configured on a virtual server, undisclosed requests can cause the Traf
When connection mirroring is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate in the standby BIG-IP systems in a traffic group.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2025-41414P3HIGHCVSS 7.5≥ 15.1.0, ≤ 15.1.10≥ 16.1.0, < 16.1.5+1 more2025-05-07
CVE-2025-41414 [HIGH] CWE-476 CVE-2025-41414: When HTTP/2 client and server profile is configured on a virtual server, undisclosed requests can ca
When HTTP/2 client and server profile is configured on a virtual server, undisclosed requests can cause TMM to terminate.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
CVE-2025-24497P3HIGHCVSS 7.5≥ 17.1.0, < 17.1.22025-02-05
CVE-2025-24497 [HIGH] CWE-125 CVE-2025-24497: When URL categorization is configured on a virtual server, undisclosed requests can cause TMM to ter
When URL categorization is configured on a virtual server, undisclosed requests can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2017-6144P3HIGHCVSS 7.4v12.1.0v12.1.1+1 more2017-10-20
CVE-2017-6144 [HIGH] CWE-295 CVE-2017-6144: In F5 BIG-IP PEM 12.1.0 through 12.1.2 when downloading the Type Allocation Code (TAC) database file
In F5 BIG-IP PEM 12.1.0 through 12.1.2 when downloading the Type Allocation Code (TAC) database file via HTTPS, the server's certificate is not verified. Attackers in a privileged network position may be able to launch a man-in-the-middle attack against these connections. TAC databases are used in BIG-IP PEM for Device Type and OS (DTOS) and Tethering d
nvd
CVE-2025-58071P3HIGHCVSS 7.5≥ 15.1.0, < 15.1.10.8≥ 16.1.0, < 16.1.6.1+2 more2025-10-15
CVE-2025-58071 [HIGH] CWE-457 CVE-2025-58071: When IPsec is configured on the BIG-IP system, undisclosed traffic can cause the Traffic Management
When IPsec is configured on the BIG-IP system, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2024-23979P3HIGHCVSS 7.5≥ 15.1.0, < 15.1.9≥ 16.1.0, < 16.1.4+1 more2024-02-14
CVE-2024-23979 [HIGH] CWE-770 CVE-2024-23979: When SSL Client Certificate LDAP or Certificate Revocation List Distribution Point (CRLDP) authenti
When SSL Client Certificate LDAP or Certificate Revocation List Distribution Point (CRLDP) authentication profile is configured on a virtual server, undisclosed requests can cause an increase in CPU resource utilization.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
CVE-2025-54479P3HIGHCVSS 7.5≥ 15.1.0, < 15.1.10.8≥ 16.1.0, < 16.1.6.1+2 more2025-10-15
CVE-2025-54479 [HIGH] CWE-787 CVE-2025-54479: When a classification profile is configured on a virtual server without an HTTP or HTTP/2 profile, u
When a classification profile is configured on a virtual server without an HTTP or HTTP/2 profile, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-39458P3HIGHCVSS 7.5≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+2 more2026-05-13
CVE-2026-39458 [HIGH] CWE-824 CVE-2026-39458: When a BIG-IP is configured with DNS caching (Such as a DNS profile with caching enabled, SSL Orche
When a BIG-IP is configured with DNS caching (Such as a DNS profile with caching enabled, SSL Orchestrator, Advanced WAF DoS protection), undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2024-22389P3HIGHCVSS 7.2≥ 15.1.0, < 15.1.9≥ 16.1.0, < 16.1.4+1 more2024-02-14
CVE-2024-22389 [HIGH] CWE-613 CVE-2024-22389: When BIG-IP is deployed in high availability (HA) and an iControl REST API token is updated, the cha
When BIG-IP is deployed in high availability (HA) and an iControl REST API token is updated, the change does not sync to the peer device.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd