F5 Big-Ip Sslo vulnerabilities
105 known vulnerabilities affecting f5/big-ip_sslo.
Total CVEs
105
CISA KEV
2
actively exploited
Public exploits
1
Exploited in wild
2
Severity breakdown
CRITICAL2HIGH67MEDIUM34LOW2
Vulnerabilities
Page 6 of 6
CVE-2021-22979MEDIUMCVSS 6.12021-02-12
CVE-2021-22979 [MEDIUM] CWE-79 CVE-2021-22979: On BIG-IP version 16
CVE-2021-22979: On BIG-IP version 16
On BIG-IP version 16.0.x before 16.0.1, 15.1.x before 15.1.1, 14.1.x before 14.1.2.8, 13.1.x before 13.1.3.5, and all 12.1.x versions, a reflected Cross-Site Scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility when Fraud Protection Service is provisioned and allows an attacker to execute JavaScript in the context of the current logged-in user. Note
f5
CVE-2021-22981MEDIUMCVSS 4.82021-02-12
CVE-2021-22981 [MEDIUM] CVE-2021-22981: On all versions of BIG-IP 12
CVE-2021-22981: On all versions of BIG-IP 12
On all versions of BIG-IP 12.1.x and 11.6.x, the original TLS protocol includes a weakness in the master secret negotiation that is mitigated by the Extended Master Secret (EMS) extension defined in RFC 7627. TLS connections that do not use EMS are vulnerable to man-in-the-middle attacks during renegotiation. Note: Software versions which have reached End of Software Development (Eo
f5
CVE-2020-5949HIGHCVSS 7.52020-12-11
CVE-2020-5949 [HIGH] CVE-2020-5949: On BIG-IP versions 14
CVE-2020-5949: On BIG-IP versions 14
On BIG-IP versions 14.0.0-14.0.1 and 13.1.0-13.1.3.4, certain traffic pattern sent to a virtual server configured with an FTP profile can cause the FTP channel to break.
Affected Products: BIG-IP AAM, BIG-IP AFM, BIG-IP APM, BIG-IP ASM, BIG-IP Advanced WAF, BIG-IP Analytics, BIG-IP DHD, BIG-IP DNS, BIG-IP FPS, BIG-IP GTM, BIG-IP LTM, BIG-IP Link Controller, BIG-IP PEM, BIG-IP SSLO
Affected Versions:
f5
CVE-2020-5939HIGHCVSS 7.52020-11-05
CVE-2020-5939 [HIGH] CVE-2020-5939: In versions 16
CVE-2020-5939: In versions 16
In versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.3, 15.0.0-15.0.1.3, 14.1.0-14.1.2.6, and 13.1.0-13.1.3.4, BIG-IP Virtual Edition (VE) systems on VMware, with an Intel-based 85299 Network Interface Controller (NIC) card and Single Root I/O Virtualization (SR-IOV) enabled on vSphere, may fail and leave the Traffic Management Microkernel (TMM) in a state where it cannot transmit traffic.
Affected Products: BIG-IP AAM, BIG
f5
CVE-2020-5943MEDIUMCVSS 6.52020-11-05
CVE-2020-5943 [MEDIUM] CWE-327 CVE-2020-5943: In versions 14
CVE-2020-5943: In versions 14
In versions 14.1.0-14.1.0.1 and 14.1.2.5-14.1.2.7, when a BIG-IP object is created or listed through the REST interface, the protected fields are obfuscated in the REST response, not protected via a SecureVault cryptogram as TMSH does. One example of protected fields is the GTM monitor password.
Affected Products: BIG-IP AAM, BIG-IP AFM, BIG-IP APM, BIG-IP ASM, BIG-IP Advanced WAF, BIG-IP Analytics, BIG-
f5
← Previous6 / 6