cbcvebase.

F5 Big-Iq Centralized Management vulnerabilities

86 known vulnerabilities affecting f5/big-iq_centralized_management.

Total CVEs
86
CISA KEV
3
actively exploited
Public exploits
4
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH38MEDIUM40

Vulnerabilities

Page 2 of 5
CVE-2021-22974P3HIGHCVSS 7.5≥ 6.0.0, ≤ 6.1.0≥ 7.0.0, ≤ 7.1.02021-02-12
CVE-2021-22974 [HIGH] CVE-2021-22974: On BIG-IP version 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, and 13.1.x b On BIG-IP version 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, and 13.1.x before 13.1.3.6 and all versions of BIG-IQ 7.x and 6.x, an authenticated attacker with access to iControl REST over the control plane may be able to take advantage of a race condition to execute commands with an elevated privilege level. This vulnerability is du
nvd
CVE-2018-5743P3HIGHCVSS 7.5≥ 5.0.0, ≤ 5.4.0≥ 6.0.0, ≤ 6.1.02019-10-09
CVE-2018-5743 [HIGH] CWE-770 CVE-2018-5743: By design, BIND is intended to limit the number of TCP clients that can be connected at any given ti By design, BIND is intended to limit the number of TCP clients that can be connected at any given time. The number of allowed connections is a tunable parameter which, if unset, defaults to a conservative value for most servers. Unfortunately, the code which was intended to limit the number of simultaneous connections contained an error which could be e
nvd
CVE-2020-5860P3HIGHCVSS 8.1≥ 5.2.0, ≤ 5.4.0≥ 6.0.0, ≤ 6.1.0+1 more2020-03-27
CVE-2020-5860 [HIGH] CWE-287 CVE-2020-5860: On BIG-IP 15.0.0-15.1.0.2, 14.1.0-14.1.2.3, 13.1.0-13.1.3.2, 12.1.0-12.1.5.1, and 11.5.2-11.6.5.1 an On BIG-IP 15.0.0-15.1.0.2, 14.1.0-14.1.2.3, 13.1.0-13.1.3.2, 12.1.0-12.1.5.1, and 11.5.2-11.6.5.1 and BIG-IQ 7.0.0, 6.0.0-6.1.0, and 5.2.0-5.4.0, in a High Availability (HA) network failover in Device Service Cluster (DSC), the failover service does not require a strong form of authentication and HA network failover traffic is not encrypted by Transport
nvd
CVE-2021-22997P3HIGHCVSS 7.5≥ 6.0.0, < 8.0.0vAll 7.x and 6.x versions2021-03-31
CVE-2021-22997 [HIGH] CWE-306 CVE-2021-22997: On all 7.x and 6.x versions (fixed in 8.0.0), BIG-IQ HA ElasticSearch service does not implement any On all 7.x and 6.x versions (fixed in 8.0.0), BIG-IQ HA ElasticSearch service does not implement any form of authentication for the clustering transport services, and all data used by ElasticSearch for transport is unencrypted. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
nvd
CVE-2018-15328P3HIGHCVSS 7.5≥ 5.0.0, ≤ 5.4.0≥ 6.0.0, ≤ 6.0.1+1 more2018-12-12
CVE-2018-15328 [HIGH] CWE-200 CVE-2018-15328: On BIG-IP 14.0.x, 13.x, 12.x, and 11.x, Enterprise Manager 3.1.1, BIG-IQ 6.x, 5.x, and 4.x, and iWor On BIG-IP 14.0.x, 13.x, 12.x, and 11.x, Enterprise Manager 3.1.1, BIG-IQ 6.x, 5.x, and 4.x, and iWorkflow 2.x, the passphrases for SNMPv3 users and trap destinations that are used for authentication and privacy are not handled by the BIG-IP system Secure Vault feature; they are written in the clear to the various configuration files.
nvd
CVE-2020-5858P3HIGHCVSS 7.8≥ 5.2.0, ≤ 5.4.0≥ 6.0.0, ≤ 6.1.0+1 more2020-03-27
CVE-2020-5858 [HIGH] CVE-2020-5858: On BIG-IP 15.0.0-15.0.1.2, 14.1.0-14.1.2.2, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.5.2-11.6.5.1 and On BIG-IP 15.0.0-15.0.1.2, 14.1.0-14.1.2.2, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.5.2-11.6.5.1 and BIG-IQ 7.0.0, 6.0.0-6.1.0, and 5.2.0-5.4.0, users with non-administrator roles (for example, Guest or Resource Administrator) with tmsh shell access can execute arbitrary commands with elevated privilege via a crafted tmsh command.
nvd
CVE-2019-1559P3MEDIUMCVSS 5.9≥ 6.0.0, ≤ 6.1.0≥ 7.0.0, ≤ 7.1.02019-02-27
CVE-2019-1559 [MEDIUM] CWE-203 CVE-2019-1559: If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to sen If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. If the application then behave
nvd
CVE-2021-22995P3HIGHCVSS 7.5≥ 6.0.0, ≤ 6.1.0≥ 7.0.0, ≤ 7.1.0+1 more2021-03-31
CVE-2021-22995 [HIGH] CWE-306 CVE-2021-22995: On all 7.x and 6.x versions (fixed in 8.0.0), BIG-IQ high availability (HA) when using a Quorum devi On all 7.x and 6.x versions (fixed in 8.0.0), BIG-IQ high availability (HA) when using a Quorum device for automatic failover does not implement any form of authentication with the Corosync daemon. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
nvd
CVE-2020-5873P3HIGHCVSS 7.2≥ 5.2.0, ≤ 5.4.0≥ 6.0.0, ≤ 6.1.0+1 more2020-04-30
CVE-2020-5873 [HIGH] CWE-78 CVE-2020-5873: On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.6.1-11.6.5 and BIG- On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.6.1-11.6.5 and BIG-IQ 5.2.0-7.1.0, a user associated with the Resource Administrator role who has access to the secure copy (scp) utility but does not have access to Advanced Shell (bash) can execute arbitrary commands using a maliciously crafted scp request.
nvd
CVE-2014-0101P3HIGHCVSS 7.8v4.6.02014-03-11
CVE-2014-0101 [HIGH] CWE-476 CVE-2014-0101: The sctp_sf_do_5_1D_ce function in net/sctp/sm_statefuns.c in the Linux kernel through 3.13.6 does n The sctp_sf_do_5_1D_ce function in net/sctp/sm_statefuns.c in the Linux kernel through 3.13.6 does not validate certain auth_enable and auth_capable fields before making an sctp_sf_authenticate call, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via an SCTP handshake with a modified INIT chunk and
nvd
CVE-2019-6621P3HIGHCVSS 7.2≥ 5.1.0, ≤ 5.4.0≥ 6.0.0, ≤ 6.1.0+3 more2019-07-02
CVE-2019-6621 [HIGH] CWE-78 CVE-2019-6621: On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4.1, 11.6.1-11.6.3.4, and 1 On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4.1, 11.6.1-11.6.3.4, and 11.5.2-11.5.8 and BIG-IQ 7.0.0-7.1.0.2, 6.0.0-6.1.0, and 5.1.0-5.4.0, an undisclosed iControl REST worker is vulnerable to command injection by an admin/resource admin user. This issue impacts both iControl REST and tmsh implementations.
nvd
CVE-2019-6620P3HIGHCVSS 7.2≥ 5.1.0, ≤ 5.4.0≥ 6.0.0, ≤ 6.1.02019-07-02
CVE-2019-6620 [HIGH] CWE-78 CVE-2019-6620: On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.5, 13.0.0-13.1.1.4, 12.1.0-12.1.4.1, and 11.5.1-11.6.4 and On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.5, 13.0.0-13.1.1.4, 12.1.0-12.1.4.1, and 11.5.1-11.6.4 and BIG-IQ 6.0.0-6.1.0 and 5.1.0-5.4.0, an undisclosed iControl REST worker vulnerable to command injection for an Administrator user.
nvd
CVE-2022-34844P3HIGHCVSS 7.5v7.0.0v7.1.0+4 more2022-08-04
CVE-2022-34844 [HIGH] CWE-20 CVE-2022-34844: In BIG-IP Versions 16.1.x before 16.1.3.1 and 15.1.x before 15.1.6.1, and all versions of BIG-IQ 8.x In BIG-IP Versions 16.1.x before 16.1.3.1 and 15.1.x before 15.1.6.1, and all versions of BIG-IQ 8.x, when the Data Plane Development Kit (DPDK)/Elastic Network Adapter (ENA) driver is used with BIG-IP or BIG-IQ on Amazon Web Services (AWS) systems, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Successful exploita
nvd
CVE-2015-4047P3HIGHCVSS 7.8v4.6.02015-05-29
CVE-2015-4047 [HIGH] CWE-476 CVE-2015-4047: racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL poin racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a series of crafted UDP requests.
nvd
CVE-2024-24775P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.3.02024-02-14
CVE-2024-24775 [HIGH] CWE-476 CVE-2024-24775: When a virtual server is enabled with VLAN group and SNAT listener is configured, undisclosed traffi When a virtual server is enabled with VLAN group and SNAT listener is configured, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
CVE-2024-23314P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.3.02024-02-14
CVE-2024-23314 [HIGH] CWE-908 CVE-2024-23314: When HTTP/2 is configured on BIG-IP or BIG-IP Next SPK systems, undisclosed responses can cause the When HTTP/2 is configured on BIG-IP or BIG-IP Next SPK systems, undisclosed responses can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
CVE-2022-23009P3HIGHCVSS 7.2v8.0.0v8.x before 8.1.02022-01-25
CVE-2022-23009 [HIGH] CWE-863 CVE-2022-23009: On BIG-IQ Centralized Management 8.x before 8.1.0, an authenticated administrative role user on a BI On BIG-IQ Centralized Management 8.x before 8.1.0, an authenticated administrative role user on a BIG-IQ managed BIG-IP device can access other BIG-IP devices managed by the same BIG-IQ system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2024-23979P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.3.02024-02-14
CVE-2024-23979 [HIGH] CWE-770 CVE-2024-23979: When SSL Client Certificate LDAP or Certificate Revocation List Distribution Point (CRLDP) authenti When SSL Client Certificate LDAP or Certificate Revocation List Distribution Point (CRLDP) authentication profile is configured on a virtual server, undisclosed requests can cause an increase in CPU resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
CVE-2024-22389P3HIGHCVSS 7.2≥ 8.0.0, ≤ 8.3.02024-02-14
CVE-2024-22389 [HIGH] CWE-613 CVE-2024-22389: When BIG-IP is deployed in high availability (HA) and an iControl REST API token is updated, the cha When BIG-IP is deployed in high availability (HA) and an iControl REST API token is updated, the change does not sync to the peer device. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
CVE-2020-5869P3CRITICALCVSS 9.1≥ 5.2.0, ≤ 5.4.0≥ 6.0.0, ≤ 6.1.0+2 more2020-04-24
CVE-2020-5869 [CRITICAL] CWE-924 CVE-2020-5869: In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization is not secure by TLS and may allow on- In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization is not secure by TLS and may allow on-path attackers to read / modify confidential data in transit.
nvd
F5 Big-Iq Centralized Management vulnerabilities | cvebase