cbcvebase.

F5 Big-Ip Websafe vulnerabilities

169 known vulnerabilities affecting f5/big-ip_websafe.

Total CVEs
169
CISA KEV
3
actively exploited
Public exploits
3
Exploited in wild
4
Severity breakdown
CRITICAL7HIGH97MEDIUM64LOW1

Vulnerabilities

Page 1 of 9
CVE-2023-46747P1CRITICALCVSS 9.8KEVPoCRansomware≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, ≤ 14.1.5+3 more2023-10-26
CVE-2023-46747 [CRITICAL] CWE-288 CVE-2023-46747: Undisclosed requests may bypass configuration utility authentication, allowing an attacker with netw Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
CVE-2023-44487P1HIGHCVSS 7.5KEVPoC≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, ≤ 14.1.5+3 more2023-10-10
CVE-2023-44487 [HIGH] CWE-400 CVE-2023-44487: The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancell The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
nvd
CVE-2023-46748P1HIGHCVSS 8.8KEV≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, ≤ 14.1.5+3 more2023-10-26
CVE-2023-46748 [HIGH] CWE-89 CVE-2023-46748: An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are
nvd
CVE-2016-5700P1CRITICALCVSS 9.8Exploitedv11.6.0v11.6.1+2 more2016-10-03
CVE-2016-5700 [CRITICAL] CWE-284 CVE-2016-5700: Virtual servers in F5 BIG-IP systems 11.5.0, 11.5.1 before HF11, 11.5.2, 11.5.3, 11.5.4 before HF2, Virtual servers in F5 BIG-IP systems 11.5.0, 11.5.1 before HF11, 11.5.2, 11.5.3, 11.5.4 before HF2, 11.6.0 before HF8, 11.6.1 before HF1, 12.0.0 before HF4, and 12.1.0 before HF2, when configured with the HTTP Explicit Proxy functionality or SOCKS profile, allow remote attackers to modify the system configuration, read system files, and possibly exec
nvd
CVE-2018-5511P3HIGHCVSS 7.2PoCv13.0.0v13.1.02018-04-13
CVE-2018-5511 [HIGH] CWE-470 CVE-2018-5511: On F5 BIG-IP 13.1.0-13.1.0.3 or 13.0.0, when authenticated administrative users execute commands in On F5 BIG-IP 13.1.0-13.1.0.3 or 13.0.0, when authenticated administrative users execute commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, restrictions on allowed commands may not be enforced.
nvd
CVE-2025-31644P2HIGHCVSS 8.7≥ 15.1.0, < 15.1.10.7≥ 16.1.0, < 16.1.6+1 more2025-05-07
CVE-2025-31644 [HIGH] CWE-77 CVE-2025-31644: When running in Appliance mode, a command injection vulnerability exists in an undisclosed iControl When running in Appliance mode, a command injection vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command which may allow an authenticated attacker with administrator role privileges to execute arbitrary system commands. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions
nvd
CVE-2023-41373P2CRITICALCVSS 9.9≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, < 14.1.5.6+3 more2023-10-10
CVE-2023-41373 [CRITICAL] CWE-22 CVE-2023-41373: A directory traversal vulnerability exists in the BIG-IP Configuration Utility that may allow an au A directory traversal vulnerability exists in the BIG-IP Configuration Utility that may allow an authenticated attacker to execute commands on the BIG-IP system. For BIG-IP system running in Appliance mode, a successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (
nvd
CVE-2025-20029P2HIGHCVSS 8.8≥ 15.1.0, < 15.1.10.6≥ 16.1.0, < 16.1.5.2+1 more2025-02-05
CVE-2025-20029 [HIGH] CWE-78 CVE-2025-20029: Command injection vulnerability exists in iControl REST and BIG-IP TMOS Shell (tmsh) save command, w Command injection vulnerability exists in iControl REST and BIG-IP TMOS Shell (tmsh) save command, which may allow an authenticated attacker to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2002-20001P3HIGHCVSS 7.5≥ 13.1.0, ≤ 17.1.2v17.5.02021-11-11
CVE-2002-20001 [HIGH] CWE-400 CVE-2002-20001: The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arb The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network bandwidth. The attack may be more disr
nvd
CVE-2026-41957P2HIGHCVSS 8.8≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+1 more2026-05-13
CVE-2026-41957 [HIGH] CWE-502 CVE-2026-41957: An authenticated remote code execution vulnerability through undisclosed vectors exists in the BIG-I An authenticated remote code execution vulnerability through undisclosed vectors exists in the BIG-IP and BIG-IQ Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-41225P3CRITICALCVSS 9.1≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+2 more2026-05-13
CVE-2026-41225 [CRITICAL] CWE-648 CVE-2026-41225: A vulnerability exists in iControl REST where a highly privileged, authenticated attacker with at le A vulnerability exists in iControl REST where a highly privileged, authenticated attacker with at least the Manager role can create configuration objects that allow running arbitrary commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2025-59481P3HIGHCVSS 8.7≥ 15.1.0, < 15.1.10.8≥ 16.1.0, < 16.1.6.1+2 more2025-10-15
CVE-2025-59481 [HIGH] CWE-250 CVE-2025-59481: A vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may A vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with at least resource administrator role to execute arbitrary system commands with higher privileges. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached
nvd
CVE-2024-45844P3HIGHCVSS 7.2≥ 15.1.0, < 15.1.10.5≥ 16.1.0, < 16.1.5+1 more2024-10-16
CVE-2024-45844 [HIGH] CWE-306 CVE-2024-45844: BIG-IP monitor functionality may allow an attacker to bypass access control restrictions, regardless BIG-IP monitor functionality may allow an attacker to bypass access control restrictions, regardless of the port lockdown settings. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2025-61958P3HIGHCVSS 8.7≥ 15.1.0, < 15.1.10.8≥ 16.1.0, < 16.1.6.1+2 more2025-10-15
CVE-2025-61958 [HIGH] CWE-250 CVE-2025-61958: A vulnerability exists in the iHealth command that may allow an authenticated attacker with at least A vulnerability exists in the iHealth command that may allow an authenticated attacker with at least a resource administrator role to bypass tmsh restrictions and gain access to a bash shell. For BIG-IP systems running in Appliance mode, a successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reache
nvd
CVE-2026-34176P3HIGHCVSS 8.7≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+2 more2026-05-13
CVE-2026-34176 [HIGH] CWE-78 CVE-2026-34176: When running in Appliance mode, an authenticated remote command injection vulnerability exists in an When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-32673P3HIGHCVSS 8.7≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+2 more2026-05-13
CVE-2026-32673 [HIGH] CWE-250 CVE-2026-32673: A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system commands with higher privileges. In appliance mode deployments, a successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reache
nvd
CVE-2017-6131P3CRITICALCVSS 9.8v12.0.0v12.1.0+3 more2017-05-23
CVE-2017-6131 [CRITICAL] CWE-798 CVE-2017-6131: In some circumstances, an F5 BIG-IP version 12.0.0 to 12.1.2 and 13.0.0 Azure cloud instance may con In some circumstances, an F5 BIG-IP version 12.0.0 to 12.1.2 and 13.0.0 Azure cloud instance may contain a default administrative password which could be used to remotely log into the BIG-IP system. The impacted administrative account is the Azure instance administrative user that was created at deployment. The root and admin accounts are not vulner
nvd
CVE-2026-41953P3HIGHCVSS 8.7≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+2 more2026-05-13
CVE-2026-41953 [HIGH] CWE-77 CVE-2026-41953: A vulnerability exists in BIG-IP systems where a highly privileged, authenticated attacker with at l A vulnerability exists in BIG-IP systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can modify configuration objects resulting in privilege escalation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-40631P3HIGHCVSS 8.7≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+2 more2026-05-13
CVE-2026-40631 [HIGH] CWE-552 CVE-2026-40631: An authenticated attacker with the Resource Administrator or Administrator role can modify configura An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects through iControl SOAP resulting in privilege escalation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-32643P3HIGHCVSS 8.7≥ 17.1.0, ≤ 17.1.3≥ 17.5.0, ≤ 17.5.1+2 more2026-05-13
CVE-2026-32643 [HIGH] CWE-250 CVE-2026-32643: A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacke A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
F5 Big-Ip Websafe vulnerabilities | cvebase