F5 Big-Ip Webaccelerator vulnerabilities
258 known vulnerabilities affecting f5/big-ip_webaccelerator.
Total CVEs
258
CISA KEV
7
actively exploited
Public exploits
13
Exploited in wild
7
Severity breakdown
CRITICAL18HIGH135MEDIUM101LOW4
Vulnerabilities
Page 5 of 13
CVE-2020-5851MEDIUMCVSS 4.6v14.1.0.2.0.45.4v14.1.0.2.0.62.42020-01-14
CVE-2020-5851 [MEDIUM] CVE-2020-5851: On impacted versions and platforms the Trusted Platform Module (TPM) system integrity check cannot d
On impacted versions and platforms the Trusted Platform Module (TPM) system integrity check cannot detect modifications to specific system components. This issue only impacts specific engineering hotfixes and platforms. NOTE: This vulnerability does not affect any of the BIG-IP major, minor or maintenance releases you obtained from downloads.f5.com. The affec
nvd
CVE-2014-5209MEDIUMCVSS 5.3≥ 10.2.1, ≤ 10.2.4v11.2.12020-01-08
CVE-2014-5209 [MEDIUM] CWE-200 CVE-2014-5209: An Information Disclosure vulnerability exists in NTP 4.2.7p25 private (mode 6/7) messages via a GET
An Information Disclosure vulnerability exists in NTP 4.2.7p25 private (mode 6/7) messages via a GET_RESTRICT control message, which could let a malicious user obtain sensitive information.
nvd
CVE-2019-6683HIGHCVSS 7.5≥ 11.5.2, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.5+4 more2019-12-23
CVE-2019-6683 [HIGH] CWE-400 CVE-2019-6683: On versions 15.0.0-15.0.1.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.
On versions 15.0.0-15.0.1.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, BIG-IP virtual servers with Loose Initiation enabled on a FastL4 profile may be subject to excessive flow usage under undisclosed conditions.
nvd
CVE-2019-6685HIGHCVSS 7.8≥ 11.5.2, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.5+4 more2019-12-23
CVE-2019-6685 [HIGH] CWE-269 CVE-2019-6685: On BIG-IP versions 15.0.0-15.0.1.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5,
On BIG-IP versions 15.0.0-15.0.1.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, users with access to edit iRules are able to create iRules which can lead to an elevation of privilege, configuration modification, and arbitrary system command execution.
nvd
CVE-2019-6676HIGHCVSS 7.5≥ 13.1.0, < 13.1.3.2≥ 14.0.0, < 14.1.2.3+1 more2019-12-23
CVE-2019-6676 [HIGH] CVE-2019-6676: On versions 15.0.0-15.0.1, 14.0.0-14.1.2.2, and 13.1.0-13.1.3.1, TMM may restart on BIG-IP Virtual E
On versions 15.0.0-15.0.1, 14.0.0-14.1.2.2, and 13.1.0-13.1.3.1, TMM may restart on BIG-IP Virtual Edition (VE) when using virtio direct descriptors and packets 2 KB or larger.
nvd
CVE-2019-6688MEDIUMCVSS 4.3≥ 11.5.2, < 11.6.5.1≥ 12.1.0, ≤ 12.1.5+4 more2019-12-23
CVE-2019-6688 [MEDIUM] CVE-2019-6688: On BIG-IP versions 15.0.0-15.0.1.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5,
On BIG-IP versions 15.0.0-15.0.1.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5 and BIG-IQ versions 6.0.0-6.1.0 and 5.2.0-5.4.0, a user is able to obtain the secret that was being used to encrypt a BIG-IP UCS backup file while sending SNMP query to the BIG-IP or BIG-IQ system, however the user can not access to the UCS fil
nvd
CVE-2019-6678MEDIUMCVSS 5.3≥ 13.1.0, < 13.1.3.2≥ 14.0.0, < 14.0.1.1+2 more2019-12-23
CVE-2019-6678 [MEDIUM] CVE-2019-6678: On BIG-IP versions 15.0.0-15.0.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, and 13.1.0-13.1.3.1, the TMM proce
On BIG-IP versions 15.0.0-15.0.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, and 13.1.0-13.1.3.1, the TMM process may restart when the packet filter feature is enabled.
nvd
CVE-2019-19151MEDIUMCVSS 5.5≥ 11.5.1, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.5+3 more2019-12-23
CVE-2019-19151 [MEDIUM] CWE-269 CVE-2019-19151: On BIG-IP versions 15.0.0-15.1.0, 14.0.0-14.1.2.3, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.5.2-11.6.5
On BIG-IP versions 15.0.0-15.1.0, 14.0.0-14.1.2.3, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, BIG-IQ versions 7.0.0, 6.0.0-6.1.0, and 5.0.0-5.4.0, iWorkflow version 2.3.0, and Enterprise Manager version 3.1.1, authenticated users granted TMOS Shell (tmsh) privileges are able access objects on the file system which would normally be disallo
nvd
CVE-2019-6679LOWCVSS 3.3≥ 11.5.9, ≤ 11.5.10≥ 11.6.4, < 11.6.5.1+5 more2019-12-23
CVE-2019-6679 [LOW] CWE-59 CVE-2019-6679: On BIG-IP versions 15.0.0-15.0.1, 14.1.0.2-14.1.2.2, 14.0.0.5-14.0.1, 13.1.1.5-13.1.3.1, 12.1.4.1-12
On BIG-IP versions 15.0.0-15.0.1, 14.1.0.2-14.1.2.2, 14.0.0.5-14.0.1, 13.1.1.5-13.1.3.1, 12.1.4.1-12.1.5, 11.6.4-11.6.5, and 11.5.9-11.5.10, the access controls implemented by scp.whitelist and scp.blacklist are not properly enforced for paths that are symlinks. This allows authenticated users with SCP access to overwrite certain configuration files that
nvd
CVE-2019-6671HIGHCVSS 7.5≥ 13.1.0, ≤ 13.1.3.1≥ 14.0.0, ≤ 14.0.1+2 more2019-11-27
CVE-2019-6671 [HIGH] CWE-401 CVE-2019-6671: On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, and 13.1.0-13.1.3.1, under certain conditions
On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, and 13.1.0-13.1.3.1, under certain conditions tmm may leak memory when processing packet fragments, leading to resource starvation.
nvd
CVE-2019-6666HIGHCVSS 7.5≥ 13.1.0, ≤ 13.1.1.4≥ 14.0.0, ≤ 14.0.0.4+2 more2019-11-27
CVE-2019-6666 [HIGH] CVE-2019-6666: On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, and 13.1.0-13.1.1.4, the TMM process may
On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, and 13.1.0-13.1.1.4, the TMM process may produce a core file when an upstream server or cache sends the BIG-IP an invalid age header value.
nvd
CVE-2019-6667HIGHCVSS 7.5≥ 11.5.1, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.4.1+4 more2019-11-27
CVE-2019-6667 [HIGH] CWE-400 CVE-2019-6667: On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.1.0-13.1.1.5, 12.1.0-12.1.4.1, and 11.
On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.1.0-13.1.1.5, 12.1.0-12.1.4.1, and 11.5.1-11.6.5, under certain conditions, TMM may consume excessive resources when processing traffic for a Virtual Server with the FIX (Financial Information eXchange) profile applied.
nvd
CVE-2019-6669HIGHCVSS 7.5≥ 11.5.1, ≤ 11.6.5.1≥ 12.1.0, ≤ 12.1.5+4 more2019-11-27
CVE-2019-6669 [HIGH] CVE-2019-6669: On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.1-11
On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.1-11.6.5.1, undisclosed traffic flow may cause TMM to restart under some circumstances.
nvd
CVE-2019-6670MEDIUMCVSS 4.4≥ 11.5.1, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.5+4 more2019-11-27
CVE-2019-6670 [MEDIUM] CWE-312 CVE-2019-6670: On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.1-11
On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.1-11.6.5, vCMP hypervisors are incorrectly exposing the plaintext unit key for their vCMP guests on the filesystem.
nvd
CVE-2019-6660HIGHCVSS 7.5≥ 13.1.0, < 13.1.3≥ 14.0.0, < 14.0.1.1+1 more2019-11-15
CVE-2019-6660 [HIGH] CWE-400 CVE-2019-6660: On BIG-IP 14.1.0-14.1.2, 14.0.0-14.0.1, and 13.1.0-13.1.1, undisclosed HTTP requests may consume exc
On BIG-IP 14.1.0-14.1.2, 14.0.0-14.0.1, and 13.1.0-13.1.1, undisclosed HTTP requests may consume excessive amounts of systems resources which may lead to a denial of service.
nvd
CVE-2019-6659HIGHCVSS 7.5≥ 14.0.0, < 14.1.0.22019-11-15
CVE-2019-6659 [HIGH] CVE-2019-6659: On version 14.0.0-14.1.0.1, BIG-IP virtual servers with TLSv1.3 enabled may experience a denial of s
On version 14.0.0-14.1.0.1, BIG-IP virtual servers with TLSv1.3 enabled may experience a denial of service due to undisclosed incoming messages.
nvd
CVE-2019-6664HIGHCVSS 7.5≥ 14.1.0, < 14.1.2v15.0.02019-11-15
CVE-2019-6664 [HIGH] CVE-2019-6664: On BIG-IP 15.0.0 and 14.1.0-14.1.0.6, under certain conditions, network protections on the managemen
On BIG-IP 15.0.0 and 14.1.0-14.1.0.6, under certain conditions, network protections on the management port do not follow current best practices.
nvd
CVE-2019-6663MEDIUMCVSS 5.5≥ 11.5.2, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.5+3 more2019-11-15
CVE-2019-6663 [MEDIUM] CWE-20 CVE-2019-6663: The BIG-IP 15.0.0-15.0.1, 14.0.0-14.1.2.2, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.1-11.6.5.1, BIG-
The BIG-IP 15.0.0-15.0.1, 14.0.0-14.1.2.2, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.1-11.6.5.1, BIG-IQ 7.0.0, 6.0.0-6.1.0, and 5.2.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1 configuration utility is vulnerable to Anti DNS Pinning (DNS Rebinding) attack.
nvd
CVE-2019-6662MEDIUMCVSS 6.5≥ 13.1.0, < 13.1.1.52019-11-15
CVE-2019-6662 [MEDIUM] CWE-532 CVE-2019-6662: On BIG-IP 13.1.0-13.1.1.4, sensitive information is logged into the local log files and/or remote lo
On BIG-IP 13.1.0-13.1.1.4, sensitive information is logged into the local log files and/or remote logging targets when restjavad processes an invalid request. Users with access to the log files would be able to view that data.
nvd
CVE-2019-6657MEDIUMCVSS 6.1≥ 11.5.2, ≤ 11.6.5≥ 12.1.0, ≤ 12.1.5+1 more2019-11-01
CVE-2019-6657 [MEDIUM] CWE-79 CVE-2019-6657: On BIG-IP 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, a reflected cross-site scripting (XSS
On BIG-IP 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, a reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Traffic Management User Interface (TMUI), also known as the BIG-IP Configuration utility.
nvd