F5 Big-Ip Websafe vulnerabilities
136 known vulnerabilities affecting f5/big-ip_websafe.
Total CVEs
136
CISA KEV
3
actively exploited
Public exploits
3
Exploited in wild
3
Severity breakdown
CRITICAL6HIGH81MEDIUM47LOW2
Vulnerabilities
Page 3 of 7
CVE-2024-28889MEDIUMCVSS 5.9≥ 15.1.0, < 15.1.10.4≥ 16.1.0, < 16.1.4.3+1 more2024-05-08
CVE-2024-28889 [MEDIUM] CWE-825 CVE-2024-28889:
When an SSL profile with alert timeout is configured with a non-default value on a virtual server
When an SSL profile with alert timeout is configured with a non-default value on a virtual server, undisclosed traffic along with conditions beyond the attacker's control can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2024-32761MEDIUMCVSS 6.5≥ 15.1.0, < 15.1.102024-05-08
CVE-2024-32761 [MEDIUM] CWE-119 CVE-2024-32761: Under certain conditions, a data leak may occur in the Traffic Management Microkernels (TMMs) of BIG
Under certain conditions, a data leak may occur in the Traffic Management Microkernels (TMMs) of BIG-IP tenants running on VELOS and rSeries platforms. This leak occurs randomly and cannot be deliberately triggered. If it occurs, it may leak up to 64 bytes of non-contiguous randomized bytes. Under rare conditions, this may lead to a TMM restart, aff
nvd
CVE-2024-33604MEDIUMCVSS 6.1≥ 15.1.0, < 15.1.10.4≥ 16.1.0, < 16.1.4.3+1 more2024-05-08
CVE-2024-33604 [MEDIUM] CWE-79 CVE-2024-33604:
A reflected cross-site scripting (XSS) vulnerability exist in undisclosed page of the BIG-IP Config
A reflected cross-site scripting (XSS) vulnerability exist in undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
CVE-2024-27202MEDIUMCVSS 4.7≥ 15.1.0, < 15.1.10.4≥ 16.1.0, < 16.1.4.3+1 more2024-05-08
CVE-2024-27202 [MEDIUM] CWE-79 CVE-2024-27202:
A DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Co
A DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-46747CRITICALCVSS 9.8KEVPoC≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, ≤ 14.1.5+3 more2023-10-26
CVE-2023-46747 [CRITICAL] CWE-288 CVE-2023-46747: Undisclosed requests may bypass configuration utility authentication, allowing an attacker with netw
Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
CVE-2023-46748HIGHCVSS 8.8KEV≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, ≤ 14.1.5+3 more2023-10-26
CVE-2023-46748 [HIGH] CWE-89 CVE-2023-46748: An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which
may
An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which
may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresses to execute arbitrary system commands.
Note: Software versions which have reached End of Technical Support (EoTS) a
nvd
CVE-2023-41373CRITICALCVSS 9.9≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, < 14.1.5.6+3 more2023-10-10
CVE-2023-41373 [CRITICAL] CWE-22 CVE-2023-41373:
A directory traversal vulnerability exists in the BIG-IP Configuration Utility that may allow an au
A directory traversal vulnerability exists in the BIG-IP Configuration Utility that may allow an authenticated attacker to execute commands on the BIG-IP system. For BIG-IP system running in Appliance mode, a successful exploit can allow the attacker to cross a security boundary.
Note: Software versions which have reached End of Technical Support
nvd
CVE-2023-41085HIGHCVSS 7.5≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, ≤ 14.1.5+2 more2023-10-10
CVE-2023-41085 [HIGH] CWE-755 CVE-2023-41085:
When IPSec is configured on a Virtual Server, undisclosed traffic can cause TMM to terminate.
Not
When IPSec is configured on a Virtual Server, undisclosed traffic can cause TMM to terminate.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-44487HIGHCVSS 7.5KEVPoC≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, ≤ 14.1.5+3 more2023-10-10
CVE-2023-44487 [HIGH] CWE-400 CVE-2023-44487: The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancell
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
nvd
CVE-2023-42768HIGHCVSS 7.2≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, ≤ 14.1.5+2 more2023-10-10
CVE-2023-42768 [HIGH] CWE-613 CVE-2023-42768:
When a non-admin user has been assigned an administrator role via an iControl REST PUT request and
When a non-admin user has been assigned an administrator role via an iControl REST PUT request and later the user's role is reverted back to a non-admin role via the Configuration utility, tmsh, or iControl REST. BIG-IP non-admin user can still have access to iControl REST admin resource. Note: Software versions which have reached End of Technical Supp
nvd
CVE-2023-40542HIGHCVSS 7.5≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, ≤ 14.1.5+2 more2023-10-10
CVE-2023-40542 [HIGH] CWE-770 CVE-2023-40542: When TCP Verified Accept is enabled on a TCP profile that is configured on a Virtual Server, undiscl
When TCP Verified Accept is enabled on a TCP profile that is configured on a Virtual Server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
CVE-2023-40537HIGHCVSS 8.1≥ 13.1.0, ≤ 14.1.5≥ 15.1.0, < 15.1.9+1 more2023-10-10
CVE-2023-40537 [HIGH] CWE-613 CVE-2023-40537:
An authenticated user's session cookie may remain valid for a limited time after logging out from t
An authenticated user's session cookie may remain valid for a limited time after logging out from the BIG-IP Configuration utility on a multi-blade VIPRION platform.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-43746HIGHCVSS 8.7≥ 13.1.0, ≤ 14.1.5≥ 15.1.0, < 15.1.9+1 more2023-10-10
CVE-2023-43746 [HIGH] CWE-267 CVE-2023-43746:
When running in Appliance mode, an authenticated user assigned the Administrator role may be able t
When running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing BIG-IP external monitor on a BIG-IP system. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evalu
nvd
CVE-2023-40534HIGHCVSS 7.5≥ 16.1.0, < 16.1.4.1v17.1.02023-10-10
CVE-2023-40534 [HIGH] CWE-401 CVE-2023-40534: When a client-side HTTP/2 profile and the HTTP MRF Router option are enabled for a virtual server, a
When a client-side HTTP/2 profile and the HTTP MRF Router option are enabled for a virtual server, and an iRule using the HTTP_REQUEST event or Local Traffic Policy are associated with the virtual server, undisclosed requests can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-43611HIGHCVSS 7.8≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, ≤ 14.1.5+2 more2023-10-10
CVE-2023-43611 [HIGH] CVE-2023-43611:
The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges d
The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installation process. This vulnerability is due to an incomplete fix for CVE-2023-38418. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
CVE-2023-45219MEDIUMCVSS 4.4≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, ≤ 14.1.5+2 more2023-10-10
CVE-2023-45219 [MEDIUM] CWE-200 CVE-2023-45219:
Exposure of Sensitive Information vulnerability exist in an undisclosed BIG-IP TMOS shell (tmsh) co
Exposure of Sensitive Information vulnerability exist in an undisclosed BIG-IP TMOS shell (tmsh) command which may allow an authenticated attacker with resource administrator role privileges to view sensitive information.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-43485MEDIUMCVSS 5.5≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, ≤ 14.1.5+2 more2023-10-10
CVE-2023-43485 [MEDIUM] CWE-532 CVE-2023-43485:
When TACACS+ audit forwarding is configured on BIG-IP or BIG-IQ system, sharedsecret is logged in p
When TACACS+ audit forwarding is configured on BIG-IP or BIG-IQ system, sharedsecret is logged in plaintext in the audit log. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-41964MEDIUMCVSS 6.5≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, ≤ 14.1.5+2 more2023-10-10
CVE-2023-41964 [MEDIUM] CWE-312 CVE-2023-41964:
The BIG-IP and BIG-IQ systems do not encrypt some sensitive information written to Database (DB) va
The BIG-IP and BIG-IQ systems do not encrypt some sensitive information written to Database (DB) variables.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-3470MEDIUMCVSS 6.1≥ 13.1.0, < 13.1.4≥ 14.1.0, < 14.1.4+1 more2023-08-02
CVE-2023-3470 [MEDIUM] CWE-1391 CVE-2023-3470:
Specific F5 BIG-IP platforms with Cavium Nitrox FIPS HSM cards generate a deterministic password fo
Specific F5 BIG-IP platforms with Cavium Nitrox FIPS HSM cards generate a deterministic password for the Crypto User account. The predictable nature of the password allows an authenticated user with TMSH access to the BIG-IP system, or anyone with physical access to the FIPS HSM, the information required to generate the correct password. On vCMP syst
nvd
CVE-2023-38138MEDIUMCVSS 6.1≥ 13.1.0, ≤ 13.1.5≥ 14.1.0, < 14.1.5.5+3 more2023-08-02
CVE-2023-38138 [HIGH] CWE-79 CVE-2023-38138:
A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Co
A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd