cbcvebase.

F5 Big-Ip Ssl Orchestrator vulnerabilities

141 known vulnerabilities affecting f5/big-ip_ssl_orchestrator.

Total CVEs
141
CISA KEV
3
actively exploited
Public exploits
2
Exploited in wild
3
Severity breakdown
CRITICAL3HIGH86MEDIUM51LOW1

Vulnerabilities

Page 4 of 8
CVE-2021-23012P3HIGHCVSS 8.2≥ 13.1.0, < 13.1.4≥ 14.1.0, < 14.1.4+2 more2021-05-10
CVE-2021-23012 [HIGH] CWE-78 CVE-2021-23012: On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, and 13.1.x be On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, and 13.1.x before 13.1.4, lack of input validation for items used in the system support functionality may allow users granted either "Resource Administrator" or "Administrator" roles to execute arbitrary bash commands on BIG-IP. Note: Software versions which have rea
nvd
CVE-2021-23011P3HIGHCVSS 7.5≥ 11.6.1, < 11.6.5.3≥ 12.1.0, < 12.1.6+4 more2021-05-10
CVE-2021-23011 [HIGH] CWE-400 CVE-2021-23011: On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before 13.1.4 On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before 13.1.4, 12.1.x before 12.1.6, and 11.6.x before 11.6.5.3, when the BIG-IP system is buffering packet fragments for reassembly, the Traffic Management Microkernel (TMM) may consume an excessive amount of resources, eventually leading to a restart and failover
nvd
CVE-2021-23045P3HIGHCVSS 7.5≥ 12.1.0, ≤ 12.1.6≥ 13.1.0, < 13.1.4.1+3 more2021-09-14
CVE-2021-23045 [HIGH] CWE-20 CVE-2021-23045: On BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, 13.1.x bef On BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, 13.1.x before 13.1.4.1, and all versions of 12.1.x, when an SCTP profile with multiple paths is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of
nvd
CVE-2023-22340P3HIGHCVSS 7.5≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, < 14.1.5.3+3 more2023-02-01
CVE-2023-22340 [HIGH] CWE-476 CVE-2023-22340: On BIG-IP versions 16.1.x before 16.1.3.3, 15.1.x before 15.1.8, 14.1.x before 14.1.5.3, and all ver On BIG-IP versions 16.1.x before 16.1.3.3, 15.1.x before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a SIP profile is configured on a Message Routing type virtual server, undisclosed traffic can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-22842P3HIGHCVSS 7.5≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, < 14.1.5.3+2 more2023-02-01
CVE-2023-22842 [HIGH] CWE-121 CVE-2023-22842: On BIG-IP versions 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all v On BIG-IP versions 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a SIP profile is configured on a Message Routing type virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS)
nvd
CVE-2023-40542P3HIGHCVSS 7.5≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, ≤ 14.1.5+2 more2023-10-10
CVE-2023-40542 [HIGH] CWE-770 CVE-2023-40542: When TCP Verified Accept is enabled on a TCP profile that is configured on a Virtual Server, undiscl When TCP Verified Accept is enabled on a TCP profile that is configured on a Virtual Server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
CVE-2025-21087P3HIGHCVSS 7.5≥ 15.1.0, ≤ 15.1.10≥ 16.1.0, < 16.1.6+1 more2025-02-05
CVE-2025-21087 [HIGH] CWE-400 CVE-2025-21087: When Client or Server SSL profiles are configured on a Virtual Server, or DNSSEC signing operations When Client or Server SSL profiles are configured on a Virtual Server, or DNSSEC signing operations are in use, undisclosed traffic can cause an increase in memory and CPU resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
CVE-2025-41433P3HIGHCVSS 7.5≥ 15.1.0, ≤ 15.1.10≥ 16.1.0, < 16.1.5+1 more2025-05-07
CVE-2025-41433 [HIGH] CWE-476 CVE-2025-41433: When a Session Initiation Protocol (SIP) message routing framework (MRF) application layer gateway ( When a Session Initiation Protocol (SIP) message routing framework (MRF) application layer gateway (ALG) profile is configured on a Message Routing virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2025-41399P3HIGHCVSS 7.5≥ 15.1.0, < 15.1.9≥ 16.1.0, < 16.1.4+1 more2025-05-07
CVE-2025-41399 [HIGH] CWE-404 CVE-2025-41399: When a Stream Control Transmission Protocol (SCTP) profile is configured on a virtual server, undisc When a Stream Control Transmission Protocol (SCTP) profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2025-61990P3HIGHCVSS 7.5≥ 15.1.0, < 15.1.10.8≥ 16.1.0, < 16.1.6.1+2 more2025-10-15
CVE-2025-61990 [HIGH] CWE-415 CVE-2025-61990: When using a multi-bladed platform with more than one blade, undisclosed traffic can cause the Traff When using a multi-bladed platform with more than one blade, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-24464P3MEDIUMCVSS 6.8≥ 16.1.0, ≤ 16.1.6v21.0.0+2 more2026-05-13
CVE-2026-24464 [MEDIUM] CWE-35 CVE-2026-24464: When running in Appliance mode, a directory traversal vulnerability exists in an undisclosed iContro When running in Appliance mode, a directory traversal vulnerability exists in an undisclosed iControl REST endpoint that may allow an authenticated attacker with administrator role privileges to cross a security boundary and delete files. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2021-23026P3HIGHCVSS 8.8≥ 13.1.0, ≤ 13.1.4≥ 14.1.0, ≤ 14.1.4+2 more2021-09-14
CVE-2021-23026 [HIGH] CWE-352 CVE-2021-23026: BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.x before 1 BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x and 11.6.x and all versions of BIG-IQ 8.x, 7.x, and 6.x are vulnerable to cross-site request forgery (CSRF) attacks through iControl SOAP. Note: Software versions which have reached End of Technical Support (EoTS) are
nvd
CVE-2020-5939P3HIGHCVSS 7.5≥ 13.1.0, ≤ 13.1.3≥ 14.1.0, < 14.1.2.7+2 more2020-11-05
CVE-2020-5939 [HIGH] CVE-2020-5939: In versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.3, 15.0.0-15.0.1.3, 14.1.0-14.1.2.6, and 13.1.0-13.1.3.4, In versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.3, 15.0.0-15.0.1.3, 14.1.0-14.1.2.6, and 13.1.0-13.1.3.4, BIG-IP Virtual Edition (VE) systems on VMware, with an Intel-based 85299 Network Interface Controller (NIC) card and Single Root I/O Virtualization (SR-IOV) enabled on vSphere, may fail and leave the Traffic Management Microkernel (TMM) in a state where it canno
nvd
CVE-2021-23009P3HIGHCVSS 7.5≥ 15.1.0, < 15.1.3≥ 16.0.0, < 16.0.1.12021-05-10
CVE-2021-23009 [HIGH] CWE-835 CVE-2021-23009: On BIG-IP version 16.0.x before 16.0.1.1 and 15.1.x before 15.1.3, malformed HTTP/2 requests may cau On BIG-IP version 16.0.x before 16.0.1.1 and 15.1.x before 15.1.3, malformed HTTP/2 requests may cause an infinite loop which causes a Denial of Service for Data Plane traffic. TMM takes the configured HA action when the TMM process is aborted. There is no control plane exposure, this is a data plane issue only. Note: Software versions which have reac
nvd
CVE-2023-43611P3HIGHCVSS 7.8≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, ≤ 14.1.5+2 more2023-10-10
CVE-2023-43611 [HIGH] CVE-2023-43611: The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges d The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installation process. This vulnerability is due to an incomplete fix for CVE-2023-38418. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
CVE-2023-23555P3HIGHCVSS 7.5≥ 14.1.5, < 14.1.5.3≥ 15.1.4, < 15.1.82023-02-01
CVE-2023-23555 [HIGH] CWE-665 CVE-2023-23555: On BIG-IP Virtual Edition versions 15.1x beginning in 15.1.4 to before 15.1.8 and 14.1.x beginning i On BIG-IP Virtual Edition versions 15.1x beginning in 15.1.4 to before 15.1.8 and 14.1.x beginning in 14.1.5 to before 14.1.5.3, and BIG-IP SPK beginning in 1.5.0 to before 1.6.0, when FastL4 profile is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which hav
nvd
CVE-2023-22664P3HIGHCVSS 7.5≥ 16.1.0, < 16.1.3.3≥ 17.0.0, < 17.0.0.22023-02-01
CVE-2023-22664 [HIGH] CWE-400 CVE-2023-22664: On BIG-IP versions 17.0.x before 17.0.0.2 and 16.1.x before 16.1.3.3, and BIG-IP SPK starting in ver On BIG-IP versions 17.0.x before 17.0.0.2 and 16.1.x before 16.1.3.3, and BIG-IP SPK starting in version 1.6.0, when a client-side HTTP/2 profile and the HTTP MRF Router option are enabled for a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support
nvd
CVE-2023-41085P3HIGHCVSS 7.5≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, ≤ 14.1.5+2 more2023-10-10
CVE-2023-41085 [HIGH] CWE-755 CVE-2023-41085: When IPSec is configured on a Virtual Server, undisclosed traffic can cause TMM to terminate. Not When IPSec is configured on a Virtual Server, undisclosed traffic can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2025-20058P3HIGHCVSS 7.5≥ 15.1.0, ≤ 15.1.10≥ 16.1.0, < 16.1.6+1 more2025-02-05
CVE-2025-20058 [HIGH] CWE-400 CVE-2025-20058: When a BIG-IP message routing profile is configured on a virtual server, undisclosed traffic can cau When a BIG-IP message routing profile is configured on a virtual server, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
CVE-2025-41430P3HIGHCVSS 7.5≥ 15.1.0, ≤ 15.1.9≥ 16.1.0, < 16.1.4+2 more2025-10-15
CVE-2025-41430 [HIGH] CWE-770 CVE-2025-41430: When BIG-IP SSL Orchestrator is enabled, undisclosed traffic can cause the Traffic Management Microk When BIG-IP SSL Orchestrator is enabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd