cbcvebase.

F5 Big-Iq Centralized Management vulnerabilities

86 known vulnerabilities affecting f5/big-iq_centralized_management.

Total CVEs
86
CISA KEV
3
actively exploited
Public exploits
4
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH38MEDIUM40

Vulnerabilities

Page 1 of 5
CVE-2021-22986P1CRITICALCVSS 9.8KEVPoCRansomware≥ 6.0.0, < 6.1.0≥ 7.0.0, < 7.0.0.2+1 more2021-03-31
CVE-2021-22986 [CRITICAL] CWE-918 CVE-2021-22986: On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x befo On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an unauthenticated remote command execution vulnerability. Note: Software versions which have reached End of Softwa
nvd
CVE-2018-14634P1HIGHCVSS 7.8KEVPoC≥ 5.0.0, ≤ 5.4.0≥ 6.0.0, ≤ 6.0.1+2 more2018-09-25
CVE-2018-14634 [HIGH] CWE-190 CVE-2018-14634: An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileg An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on the system. Kernel versions 2.6.x, 3.10.x and 4.14.x are believed to be vulnerable.
nvd
CVE-2014-0196P1MEDIUMCVSS 5.5KEVPoCv4.6.02014-05-07
CVE-2014-0196 [MEDIUM] CWE-362 CVE-2014-0196: The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privileges by triggering a race condition involving read and write operations with long strings.
nvd
CVE-2022-41622P2HIGHCVSS 8.8PoC≥ 8.0.0, ≤ 8.2.0v7.1.0+2 more2022-12-07
CVE-2022-41622 [HIGH] CWE-352 CVE-2022-41622: In all versions, BIG-IP and BIG-IQ are vulnerable to cross-site request forgery (CSRF) attacks thr In all versions, BIG-IP and BIG-IQ are vulnerable to cross-site request forgery (CSRF) attacks through iControl SOAP. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2019-11479P2HIGHCVSS 7.5≥ 5.1.0, ≤ 5.4.0≥ 6.0.0, ≤ 6.1.02019-06-19
CVE-2019-11479 [HIGH] CWE-405 CVE-2019-11479: Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows a remote peer to fragment TCP resend queues significantly more than if a larger MSS were enforced. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, a
nvd
CVE-2002-20001P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.4.0v7.1.02021-11-11
CVE-2002-20001 [HIGH] CWE-400 CVE-2002-20001: The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arb The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network bandwidth. The attack may be more disr
nvd
CVE-2026-41957P2HIGHCVSS 8.8v8.4.02026-05-13
CVE-2026-41957 [HIGH] CWE-502 CVE-2026-41957: An authenticated remote code execution vulnerability through undisclosed vectors exists in the BIG-I An authenticated remote code execution vulnerability through undisclosed vectors exists in the BIG-IP and BIG-IQ Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2020-5868P2CRITICALCVSS 9.8≥ 6.0.0, ≤ 6.1.0v7.0.0+1 more2020-04-24
CVE-2020-5868 [CRITICAL] CWE-78 CVE-2020-5868: In BIG-IQ 6.0.0-7.0.0, a remote access vulnerability has been discovered that may allow a remote use In BIG-IQ 6.0.0-7.0.0, a remote access vulnerability has been discovered that may allow a remote user to execute shell commands on affected systems using HTTP requests to the BIG-IQ user interface.
nvd
CVE-2019-6642P3HIGHCVSS 8.8≥ 5.1.0, ≤ 5.4.0≥ 6.0.0, ≤ 6.1.02019-07-01
CVE-2019-6642 [HIGH] CVE-2019-6642: In BIG-IP 15.0.0, 14.0.0-14.1.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.2, and 11.5.2-11.6.4, BIG-IQ 6.0.0 In BIG-IP 15.0.0, 14.0.0-14.1.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.2, and 11.5.2-11.6.4, BIG-IQ 6.0.0-6.1.0 and 5.1.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1, authenticated users with the ability to upload files (via scp, for example) can escalate their privileges to allow root shell access from within the TMOS Shell (tmsh) interface. The tmsh inter
nvd
CVE-2016-5022P3CRITICALCVSS 9.8v4.6.02016-09-07
CVE-2016-5022 [CRITICAL] CWE-284 CVE-2016-5022: F5 BIG-IP LTM, Analytics, APM, ASM, and Link Controller 11.2.x before 11.2.1 HF16, 11.3.x, 11.4.x, 1 F5 BIG-IP LTM, Analytics, APM, ASM, and Link Controller 11.2.x before 11.2.1 HF16, 11.3.x, 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.6.1 HF1, and 12.x before 12.0.0 HF3; BIG-IP AAM, AFM, and PEM 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.6.1 HF1, and 12.x before 12.0.0 HF3; BIG-IP DNS 12.x before 12.0.0 HF3; BIG-IP Edge Gateway, Web
nvd
CVE-2026-32643P3HIGHCVSS 8.7≥ 8.4.0, ≤ 8.4.12026-05-13
CVE-2026-32643 [HIGH] CWE-250 CVE-2026-32643: A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacke A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-42406P3HIGHCVSS 8.7≥ 8.4.0, ≤ 8.4.12026-05-13
CVE-2026-42406 [HIGH] CWE-267 CVE-2026-42406: A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacke A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-20916P3HIGHCVSS 8.1v8.4.02026-05-13
CVE-2026-20916 [HIGH] CWE-22 CVE-2026-20916: An authenticated iControl REST user with low privileges can create or modify arbitrary files through An authenticated iControl REST user with low privileges can create or modify arbitrary files through an undisclosed iControl REST endpoint on the BIG-IQ system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-40698P3HIGHCVSS 8.7≥ 8.4.0, ≤ 8.4.12026-05-13
CVE-2026-40698 [HIGH] CWE-77 CVE-2026-40698: A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacke A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can create SNMP configuration objects through iControl REST or the TMOS shell (tmsh) resulting in privilege escalation. Note: Software versions which have reached End of Technical Support (EoTS) are not eva
nvd
CVE-2021-23005P3CRITICALCVSS 9.1≥ 6.0.0, < 8.0.0vAll 7.x and 6.x versions2021-03-31
CVE-2021-23005 [CRITICAL] CVE-2021-23005: On all 7.x and 6.x versions (fixed in 8.0.0), when using a Quorum device for BIG-IQ high availabilit On all 7.x and 6.x versions (fixed in 8.0.0), when using a Quorum device for BIG-IQ high availability (HA) for automatic failover, BIG-IQ does not make use of Transport Layer Security (TLS) with the Corosync protocol. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
nvd
CVE-2024-22093P3HIGHCVSS 8.7≥ 8.0.0, ≤ 8.3.02024-02-14
CVE-2024-22093 [HIGH] CWE-77 CVE-2024-22093: When running in appliance mode, an authenticated remote command injection vulnerability exists in an When running in appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint on multi-bladed systems. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
CVE-2022-35728P3CRITICALCVSS 9.8v7.0.0v7.1.0+4 more2022-08-04
CVE-2022-35728 [CRITICAL] CWE-613 CVE-2022-35728: In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x be In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, and BIG-IQ version 8.x before 8.2.0 and all versions of 7.x, an authenticated user's iControl REST token may remain valid for a limited time after logging out from the Configuration utility. Note: Software
nvd
CVE-2021-23024P3HIGHCVSS 7.2≥ 6.0.0, ≤ 6.1.0≥ 7.0.0, ≤ 7.1.0+2 more2021-06-10
CVE-2021-23024 [HIGH] CVE-2021-23024: On version 8.0.x before 8.0.0.1, and all 6.x and 7.x versions, the BIG-IQ Configuration utility has On version 8.0.x before 8.0.0.1, and all 6.x and 7.x versions, the BIG-IQ Configuration utility has an authenticated remote command execution vulnerability in undisclosed pages. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2019-10744P3CRITICALCVSS 9.1≥ 6.0.0, ≤ 6.1.0v5.4.0+1 more2019-07-26
CVE-2019-10744 [CRITICAL] CWE-1321 CVE-2019-10744: Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDe Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.
nvd
CVE-2019-6665P3CRITICALCVSS 9.4≥ 5.2.0, ≤ 5.4.0v6.0.02019-11-27
CVE-2019-6665 [CRITICAL] CVE-2019-6665: On BIG-IP ASM 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, and 13.1.0-13.1.3.1, BIG-IQ 6.0.0 and 5.2 On BIG-IP ASM 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, and 13.1.0-13.1.3.1, BIG-IQ 6.0.0 and 5.2.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1, an attacker with access to the device communication between the BIG-IP ASM Central Policy Builder and the BIG-IQ/Enterprise Manager/F5 iWorkflow will be able to set up the proxy the same way and interce
nvd
F5 Big-Iq Centralized Management vulnerabilities | cvebase