F5 Big-Iq vulnerabilities
20 known vulnerabilities affecting f5/big-iq.
Total CVEs
20
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH6MEDIUM12
Vulnerabilities
Page 1 of 1
CVE-2014-3220P3CRITICALCVSS 9.0PoCv4.1.0.2013.02014-05-05
CVE-2014-3220 [CRITICAL] CWE-255 CVE-2014-3220: F5 BIG-IQ Cloud and Security 4.0.0 through 4.1.0 allows remote authenticated users to change the pas
F5 BIG-IQ Cloud and Security 4.0.0 through 4.1.0 allows remote authenticated users to change the password of arbitrary users via the name parameter in a request to the user's page in mgmt/shared/authz/users/.
nvd
CVE-2026-41957P2HIGHCVSS 8.8≥ 8.4.0, < 8.4.12026-05-13
CVE-2026-41957 [HIGH] CWE-502 CVE-2026-41957: An authenticated remote code execution vulnerability through undisclosed vectors exists in the BIG-I
An authenticated remote code execution vulnerability through undisclosed vectors exists in the BIG-IP and BIG-IQ Configuration utility.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-32643P3HIGHCVSS 8.7≥ 8.4.0, < *2026-05-13
CVE-2026-32643 [HIGH] CWE-250 CVE-2026-32643: A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacke
A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-42406P3HIGHCVSS 8.7≥ 8.4.0, < *2026-05-13
CVE-2026-42406 [HIGH] CWE-267 CVE-2026-42406: A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacke
A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-20916P3HIGHCVSS 8.1≥ 8.4.0, < 8.4.12026-05-13
CVE-2026-20916 [HIGH] CWE-22 CVE-2026-20916: An authenticated iControl REST user with low privileges can create or modify arbitrary files through
An authenticated iControl REST user with low privileges can create or modify arbitrary files through an undisclosed iControl REST endpoint on the BIG-IQ system.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-40698P3HIGHCVSS 8.7≥ 8.4.0, < *2026-05-13
CVE-2026-40698 [HIGH] CWE-77 CVE-2026-40698: A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacke
A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can create SNMP configuration objects through iControl REST or the TMOS shell (tmsh) resulting in privilege escalation. Note: Software versions which have reached End of Technical Support (EoTS) are not eva
nvd
CVE-2019-6665P3CRITICALCVSS 9.4v6.0.0v5.2.0-5.4.02019-11-27
CVE-2019-6665 [CRITICAL] CVE-2019-6665: On BIG-IP ASM 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, and 13.1.0-13.1.3.1, BIG-IQ 6.0.0 and 5.2
On BIG-IP ASM 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, and 13.1.0-13.1.3.1, BIG-IQ 6.0.0 and 5.2.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1, an attacker with access to the device communication between the BIG-IP ASM Central Policy Builder and the BIG-IQ/Enterprise Manager/F5 iWorkflow will be able to set up the proxy the same way and interce
nvd
CVE-2020-5873P3HIGHCVSS 7.2≥ 8.0.0, < *2020-04-30
CVE-2020-5873 [HIGH] CWE-78 CVE-2020-5873: On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.6.1-11.6.5 and BIG-
On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.6.1-11.6.5 and BIG-IQ 5.2.0-7.1.0, a user associated with the Resource Administrator role who has access to the secure copy (scp) utility but does not have access to Advanced Shell (bash) can execute arbitrary commands using a maliciously crafted scp request.
nvd
CVE-2026-42937P3MEDIUMCVSS 6.5≥ 8.4.0, < *2026-05-13
CVE-2026-42937 [MEDIUM] CWE-732 CVE-2026-42937: Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) arp and
Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) arp and ndp commands, and in BIG-IP iControl REST. These vulnerabilities may allow an authenticated attacker to view adjacent network information.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-41219P3MEDIUMCVSS 6.5≥ 8.4.0, < 8.4.12026-05-13
CVE-2026-41219 [MEDIUM] CWE-532 CVE-2026-41219: An improper sanitization vulnerability exists in the BIG-IP QKView utility that allows a low-privile
An improper sanitization vulnerability exists in the BIG-IP QKView utility that allows a low-privileged attacker to read sensitive information from a QKView file.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
CVE-2022-41770P4MEDIUMCVSS 6.5≥ 8.0.0, < 8.x*≥ 7.1.0, < 7.1.x*2022-10-19
CVE-2022-41770 [MEDIUM] CWE-400 CVE-2022-41770: In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.7, 14.1.x befo
In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.7, 14.1.x before 14.1.5.1, and all versions of 13.1.x, and BIG-IQ all versions of 8.x and 7.x, an authenticated iControl REST user can cause an increase in memory resource utilization, via undisclosed requests.
nvd
CVE-2023-41964P4MEDIUMCVSS 6.5≥ 8.1.0, < *≥ 8.2.0, < 8.2.0.1.0.13.97-ENG+1 more2023-10-10
CVE-2023-41964 [MEDIUM] CWE-312 CVE-2023-41964: The BIG-IP and BIG-IQ systems do not encrypt some sensitive information written to Database (DB) va
The BIG-IP and BIG-IQ systems do not encrypt some sensitive information written to Database (DB) variables.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-41959P4MEDIUMCVSS 6.5≥ 8.4.0, < *2026-05-13
CVE-2026-41959 [MEDIUM] CWE-732 CVE-2026-41959: Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) network
Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) network diagnostics commands and in BIG-IP iControl REST. These vulnerabilities may allow an authenticated attacker to view the network status of destination systems.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluat
nvd
CVE-2023-29240P4MEDIUMCVSS 5.4≥ 8.0.0, < 8.3.02023-05-03
CVE-2023-29240 [MEDIUM] CWE-863 CVE-2023-29240: An authenticated attacker granted a Viewer or Auditor role on a BIG-IQ can upload arbitrary files us
An authenticated attacker granted a Viewer or Auditor role on a BIG-IQ can upload arbitrary files using an undisclosed iControl REST endpoint. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2024-47139P4MEDIUMCVSS 6.8≥ 8.0, < 8.2.0.12024-10-16
CVE-2024-47139 [MEDIUM] CWE-80 CVE-2024-47139: A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IQ Config
A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IQ Configuration utility that allows an attacker with the Administrator role to run JavaScript in the context of the currently logged-in user.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-41954P4MEDIUMCVSS 4.9≥ 8.4.0, < 8.4.12026-05-13
CVE-2026-41954 [MEDIUM] CWE-200 CVE-2026-41954: Sensitive information disclosure vulnerability exists in the undisclosed iControl REST endpoint and
Sensitive information disclosure vulnerability exists in the undisclosed iControl REST endpoint and TMOS Shell (tmsh) command which may allow an authenticated attacker with resource administrator role privileges to view sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2023-43485P4MEDIUMCVSS 5.5≥ 8.1.0, < *≥ 8.2.0, < 8.2.0.1.0.13.97-ENG+1 more2023-10-10
CVE-2023-43485 [MEDIUM] CWE-532 CVE-2023-43485: When TACACS+ audit forwarding is configured on BIG-IP or BIG-IQ system, sharedsecret is logged in p
When TACACS+ audit forwarding is configured on BIG-IP or BIG-IQ system, sharedsecret is logged in plaintext in the audit log. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2022-41694P4MEDIUMCVSS 4.9≥ 8.x, < 8.2.0.1≥ 7.1.0, < 7.1.x*2022-10-19
CVE-2022-41694 [MEDIUM] CWE-20 CVE-2022-41694: In BIG-IP versions 16.1.x before 16.1.3, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versi
In BIG-IP versions 16.1.x before 16.1.3, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, and BIG-IQ versions 8.x before 8.2.0.1 and all versions of 7.x, when an SSL key is imported on a BIG-IP or BIG-IQ system, undisclosed input can cause MCPD to terminate.
nvd
CVE-2019-6688P4MEDIUMCVSS 4.3vBIG-IQ 6.0.0-6.1.0v5.2.0-5.4.02019-12-23
CVE-2019-6688 [MEDIUM] CVE-2019-6688: On BIG-IP versions 15.0.0-15.0.1.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5,
On BIG-IP versions 15.0.0-15.0.1.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5 and BIG-IQ versions 6.0.0-6.1.0 and 5.2.0-5.4.0, a user is able to obtain the secret that was being used to encrypt a BIG-IP UCS backup file while sending SNMP query to the BIG-IP or BIG-IQ system, however the user can not access to the UCS fil
nvd
CVE-2023-38419P4MEDIUMCVSS 4.3≥ 8.2.0, < *≥ 8.3.0, < *2023-08-02
CVE-2023-38419 [MEDIUM] CWE-755 CVE-2023-38419: An authenticated attacker with guest privileges or higher can cause the iControl SOAP process to ter
An authenticated attacker with guest privileges or higher can cause the iControl SOAP process to terminate by sending undisclosed requests. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd