F5 Big-Ip Ssl Orchestrator vulnerabilities
141 known vulnerabilities affecting f5/big-ip_ssl_orchestrator.
Total CVEs
141
CISA KEV
3
actively exploited
Public exploits
2
Exploited in wild
3
Severity breakdown
CRITICAL3HIGH86MEDIUM51LOW1
Vulnerabilities
Page 7 of 8
CVE-2026-42781P4MEDIUMCVSS 6.5v21.0.0≥ 17.1.0, ≤ 17.1.3+1 more2026-05-13
CVE-2026-42781 [MEDIUM] CWE-835 CVE-2026-42781: When embedded Packet Velocity Acceleration (ePVA) acceleration is configured, undisclosed local ethe
When embedded Packet Velocity Acceleration (ePVA) acceleration is configured, undisclosed local ethernet traffic can cause an increase in ePVA and Traffic Management Microkernel (TMM) resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2021-23027P4MEDIUMCVSS 6.1≥ 14.1.0, ≤ 14.1.4≥ 15.1.0, ≤ 15.1.3+1 more2021-09-14
CVE-2021-23027 [MEDIUM] CWE-79 CVE-2021-23027: On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, and 14.1.x before 14.1.4.3, a DOM based c
On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, and 14.1.x before 14.1.4.3, a DOM based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to execute JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Te
nvd
CVE-2026-41954P4MEDIUMCVSS 4.9≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+2 more2026-05-13
CVE-2026-41954 [MEDIUM] CWE-200 CVE-2026-41954: Sensitive information disclosure vulnerability exists in the undisclosed iControl REST endpoint and
Sensitive information disclosure vulnerability exists in the undisclosed iControl REST endpoint and TMOS Shell (tmsh) command which may allow an authenticated attacker with resource administrator role privileges to view sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2024-33604P4MEDIUMCVSS 6.1≥ 15.1.0, < 15.1.10.4≥ 16.1.0, < 16.1.4.3+1 more2024-05-08
CVE-2024-33604 [MEDIUM] CWE-79 CVE-2024-33604: A reflected cross-site scripting (XSS) vulnerability exist in undisclosed page of the BIG-IP Config
A reflected cross-site scripting (XSS) vulnerability exist in undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
CVE-2023-22326P4MEDIUMCVSS 4.9≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, < 14.1.5.3+3 more2023-02-01
CVE-2023-22326 [MEDIUM] CWE-732 CVE-2023-22326: In BIG-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x be
In BIG-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all versions of 13.1.x, and all versions of BIG-IQ 8.x and 7.1.x, incorrect permission assignment vulnerabilities exist in the iControl REST and TMOS shell (tmsh) dig command which may allow an authenticated attacker with resource a
nvd
CVE-2023-27378P4MEDIUMCVSS 6.1≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, < 14.1.5.4+3 more2023-05-03
CVE-2023-27378 [MEDIUM] CWE-79 CVE-2023-27378: Multiple reflected cross-site scripting (XSS) vulnerabilities exist in undisclosed pages of the BIG
Multiple reflected cross-site scripting (XSS) vulnerabilities exist in undisclosed pages of the BIG-IP Configuration utility which allow an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-38138P4MEDIUMCVSS 6.1≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, < 14.1.5.5+3 more2023-08-02
CVE-2023-38138 [MEDIUM] CWE-79 CVE-2023-38138: A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Co
A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-24594P4MEDIUMCVSS 5.3v14.1.5v15.1.4.1+1 more2023-05-03
CVE-2023-24594 [MEDIUM] CWE-400 CVE-2023-24594: When an SSL profile is configured on a Virtual Server, undisclosed traffic can cause an increase in
When an SSL profile is configured on a Virtual Server, undisclosed traffic can cause an increase in CPU or SSL accelerator resource utilization.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-38423P4MEDIUMCVSS 5.4≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, < 14.1.5.5+3 more2023-08-02
CVE-2023-38423 [MEDIUM] CWE-79 CVE-2023-38423: A cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuratio
A cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-43485P4MEDIUMCVSS 5.5≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, ≤ 14.1.5+2 more2023-10-10
CVE-2023-43485 [MEDIUM] CWE-532 CVE-2023-43485: When TACACS+ audit forwarding is configured on BIG-IP or BIG-IQ system, sharedsecret is logged in p
When TACACS+ audit forwarding is configured on BIG-IP or BIG-IQ system, sharedsecret is logged in plaintext in the audit log. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-40703P4MEDIUMCVSS 5.4≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+1 more2026-05-13
CVE-2026-40703 [MEDIUM] CWE-352 CVE-2026-40703: A cross-site request forgery (CSRF) vulnerability exists in the dashboard of the BIG-IP Configuratio
A cross-site request forgery (CSRF) vulnerability exists in the dashboard of the BIG-IP Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-28406P4MEDIUMCVSS 4.3≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, < 14.1.5.4+3 more2023-05-03
CVE-2023-28406 [MEDIUM] CWE-22 CVE-2023-28406: A directory traversal vulnerability exists in an undisclosed page of the BIG-IP Configuration utilit
A directory traversal vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which may allow an authenticated attacker to read files with .xml extension. Access to restricted information is limited and the attacker does not control what information is obtained.
Note: Software versions which have reached End of Technical Sup
nvd
CVE-2021-22981P4MEDIUMCVSS 4.8≥ 11.6.1, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.52021-02-12
CVE-2021-22981 [MEDIUM] CVE-2021-22981: On all versions of BIG-IP 12.1.x and 11.6.x, the original TLS protocol includes a weakness in the ma
On all versions of BIG-IP 12.1.x and 11.6.x, the original TLS protocol includes a weakness in the master secret negotiation that is mitigated by the Extended Master Secret (EMS) extension defined in RFC 7627. TLS connections that do not use EMS are vulnerable to man-in-the-middle attacks during renegotiation. Note: Software versions which have reached End o
nvd
CVE-2024-27202P4MEDIUMCVSS 4.7≥ 15.1.0, < 15.1.10.4≥ 16.1.0, < 16.1.4.3+1 more2024-05-08
CVE-2024-27202 [MEDIUM] CWE-79 CVE-2024-27202: A DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Co
A DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-38419P4MEDIUMCVSS 4.3≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, < 14.1.5.5+3 more2023-08-02
CVE-2023-38419 [MEDIUM] CWE-755 CVE-2023-38419: An authenticated attacker with guest privileges or higher can cause the iControl SOAP process to ter
An authenticated attacker with guest privileges or higher can cause the iControl SOAP process to terminate by sending undisclosed requests. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2024-41723P4MEDIUMCVSS 4.3≥ 15.1.0, ≤ 15.1.1≥ 16.1.0, < 16.1.5+1 more2024-08-14
CVE-2024-41723 [MEDIUM] CWE-200 CVE-2024-41723: Undisclosed requests to BIG-IP iControl REST can lead to information leak of user account names. No
Undisclosed requests to BIG-IP iControl REST can lead to information leak of user account names. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-42058P4MEDIUMCVSS 4.3≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+2 more2026-05-13
CVE-2026-42058 [MEDIUM] CWE-732 CVE-2026-42058: An authenticated attacker's undisclosed requests to BIG-IP iControl REST can lead to an information
An authenticated attacker's undisclosed requests to BIG-IP iControl REST can lead to an information leak of BIG-IP local user account names. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-20732P4MEDIUMCVSS 4.3≥ 16.1.0, ≤ 16.1.6≥ 17.1.0, < 17.1.3.1+1 more2026-02-04
CVE-2026-20732 [MEDIUM] CWE-451 CVE-2026-20732: A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacke
A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-42408P4MEDIUMCVSS 4.4≥ 16.1.0, ≤ 16.1.6≥ 17.1.0, ≤ 17.1.3+1 more2026-05-13
CVE-2026-42408 [MEDIUM] CWE-312 CVE-2026-42408: When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed TMOS Shell (tmsh) command t
When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed TMOS Shell (tmsh) command that may allow a highly privileged authenticated attacker to view sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-45219P4MEDIUMCVSS 4.4≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, ≤ 14.1.5+2 more2023-10-10
CVE-2023-45219 [MEDIUM] CWE-200 CVE-2023-45219: Exposure of Sensitive Information vulnerability exist in an undisclosed BIG-IP TMOS shell (tmsh) co
Exposure of Sensitive Information vulnerability exist in an undisclosed BIG-IP TMOS shell (tmsh) command which may allow an authenticated attacker with resource administrator role privileges to view sensitive information.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd