cbcvebase.

F5 Networks Inc Big-Ip vulnerabilities

26 known vulnerabilities affecting f5_networks_inc/big-ip.

Total CVEs
26
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH13MEDIUM12LOW1

Vulnerabilities

Page 1 of 2
CVE-2016-9251P3HIGHCVSS 8.8v12.0.0 - 12.1.22017-05-09
CVE-2016-9251 [HIGH] CWE-264 CVE-2016-9251: In F5 BIG-IP 12.0.0 through 12.1.2, an authenticated attacker may be able to cause an escalation of In F5 BIG-IP 12.0.0 through 12.1.2, an authenticated attacker may be able to cause an escalation of privileges through a crafted iControl REST connection.
nvd
CVE-2016-9250P3HIGHCVSS 7.5v11.2.1v11.4.0-11.6.1+1 more2017-05-10
CVE-2016-9250 [HIGH] CWE-264 CVE-2016-9250: In F5 BIG-IP 11.2.1, 11.4.0 through 11.6.1, and 12.0.0 through 12.1.2, an unauthenticated user with In F5 BIG-IP 11.2.1, 11.4.0 through 11.6.1, and 12.0.0 through 12.1.2, an unauthenticated user with access to the control plane may be able to delete arbitrary files through an undisclosed mechanism.
nvd
CVE-2018-5536P3HIGHCVSS 7.5v13.0.0-13.1.0.7v12.1.0-12.1.3.52018-07-25
CVE-2018-5536 [HIGH] CWE-772 CVE-2018-5536: A remote attacker via undisclosed measures, may be able to exploit an F5 BIG-IP APM 13.0.0-13.1.0.7 A remote attacker via undisclosed measures, may be able to exploit an F5 BIG-IP APM 13.0.0-13.1.0.7 or 12.1.0-12.1.3.5 virtual server configured with an APM per-request policy object and cause a memory leak in the APM module.
nvd
CVE-2018-5544P3HIGHCVSS 7.5v13.0.0-13.1.1v12.1.0-12.1.32018-07-31
CVE-2018-5544 [HIGH] CWE-200 CVE-2018-5544: When the F5 BIG-IP APM 13.0.0-13.1.1 or 12.1.0-12.1.3 renders certain pages (pages with a logon agen When the F5 BIG-IP APM 13.0.0-13.1.1 or 12.1.0-12.1.3 renders certain pages (pages with a logon agent or a confirm box), the BIG-IP APM may disclose configuration information such as partition and agent names via URI parameters.
nvd
CVE-2016-9256P3HIGHCVSS 7.5v12.1.0-12.1.22017-05-09
CVE-2016-9256 [HIGH] CWE-362 CVE-2016-9256: In F5 BIG-IP 12.1.0 through 12.1.2, permissions enforced by iControl can lag behind the actual permi In F5 BIG-IP 12.1.0 through 12.1.2, permissions enforced by iControl can lag behind the actual permissions assigned to a user if the role_map is not reloaded between the time the permissions are changed and the time of the user's next request. This is a race condition that occurs rarely in normal usage; the typical period in which this is possible is li
nvd
CVE-2018-5503P3HIGHCVSS 7.5v13.0.0 - 13.1.0.3v12.0.0 - 12.1.3.12018-03-22
CVE-2018-5503 [HIGH] CWE-20 CVE-2018-5503: On F5 BIG-IP versions 13.0.0 - 13.1.0.3 or 12.0.0 - 12.1.3.1, TMM may restart when processing a spec On F5 BIG-IP versions 13.0.0 - 13.1.0.3 or 12.0.0 - 12.1.3.1, TMM may restart when processing a specifically crafted page through a virtual server with an associated PEM policy that has content insertion as an action.
nvd
CVE-2018-15326P3HIGHCVSS 7.5v14.0.0-14.0.0.2, 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, 11.6.0-11.6.3.22018-10-31
CVE-2018-15326 [HIGH] CWE-295 CVE-2018-15326: In some situations on BIG-IP APM 14.0.0-14.0.0.2, 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, or 11.6.0-11.6.3 In some situations on BIG-IP APM 14.0.0-14.0.0.2, 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, or 11.6.0-11.6.3.2, the CRLDP Auth access policy agent may treat revoked certificates as valid when the BIG-IP APM system fails to download a new Certificate Revocation List.
nvd
CVE-2018-5541P3HIGHCVSS 7.5v13.0.0-13.1.0.1v12.1.0-12.1.3.5+2 more2018-07-25
CVE-2018-5541 [HIGH] CWE-400 CVE-2018-5541: When F5 BIG-IP ASM 13.0.0-13.1.0.1, 12.1.0-12.1.3.5, 11.6.0-11.6.3.1, or 11.5.1-11.5.6 is processing When F5 BIG-IP ASM 13.0.0-13.1.0.1, 12.1.0-12.1.3.5, 11.6.0-11.6.3.1, or 11.5.1-11.5.6 is processing HTTP requests, an unusually large number of parameters can cause excessive CPU usage in the BIG-IP ASM bd process.
nvd
CVE-2018-5539P3HIGHCVSS 7.5v13.0.0-13.1.0.7v12.1.0-12.1.3.5+3 more2018-07-25
CVE-2018-5539 [HIGH] CVE-2018-5539: Under certain conditions, on F5 BIG-IP ASM 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, 11.6.0-11.6.3.1, 11.5.1 Under certain conditions, on F5 BIG-IP ASM 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, 11.6.0-11.6.3.1, 11.5.1-11.5.6, or 11.2.1, when processing CSRF protections, the BIG-IP ASM bd process may restart and produce a core file.
nvd
CVE-2016-7475P3HIGHCVSS 7.5v12.0.0-12.1.0, 11.6.0-11.6.1, 11.4.0-11.5.4 HF12018-10-08
CVE-2016-7475 [HIGH] CWE-20 CVE-2016-7475: Under some circumstances on BIG-IP 12.0.0-12.1.0, 11.6.0-11.6.1, or 11.4.0-11.5.4 HF1, the Traffic M Under some circumstances on BIG-IP 12.0.0-12.1.0, 11.6.0-11.6.1, or 11.4.0-11.5.4 HF1, the Traffic Management Microkernel (TMM) may not properly clean-up pool member network connections when using SPDY or HTTP/2 virtual server profiles.
nvd
CVE-2019-6596P3HIGHCVSS 7.5v14.0.0-14.0.0.2, 13.0.0-13.1.1.1, 12.1.0-12.1.3.6, 11.6.1-11.6.3.2, 11.5.1-11.5.82019-03-13
CVE-2019-6596 [HIGH] CVE-2019-6596: In BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.1, 12.1.0-12.1.3.6, 11.6.1-11.6.3.2, or 11.5.1-11.5.8, when In BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.1, 12.1.0-12.1.3.6, 11.6.1-11.6.3.2, or 11.5.1-11.5.8, when processing fragmented ClientHello messages in a DTLS session TMM may corrupt memory eventually leading to a crash. Only systems offering DTLS connections via APM are impacted.
nvd
CVE-2016-9253P3HIGHCVSS 7.5v12.1.0-12.1.22017-05-09
CVE-2016-9253 [HIGH] CWE-20 CVE-2016-9253: In F5 BIG-IP 12.1.0 through 12.1.2, specific websocket traffic patterns may cause a disruption of se In F5 BIG-IP 12.1.0 through 12.1.2, specific websocket traffic patterns may cause a disruption of service for virtual servers configured to use the websocket profile.
nvd
CVE-2018-15331P4HIGHCVSS 7.8v13.0.0, 12.1.0-12.1.3.72018-12-20
CVE-2018-15331 [HIGH] CWE-269 CVE-2018-15331: On BIG-IP AAM 13.0.0 or 12.1.0-12.1.3.7, the dcdb_convert utility used by BIG-IP AAM fails to drop g On BIG-IP AAM 13.0.0 or 12.1.0-12.1.3.7, the dcdb_convert utility used by BIG-IP AAM fails to drop group permissions when executing helper scripts, which could be used to leverage attacks against the BIG-IP system.
nvd
CVE-2018-15335P4MEDIUMCVSS 5.9v13.0.0-13.1.x2018-12-28
CVE-2018-15335 [MEDIUM] CVE-2018-15335: When APM 13.0.0-13.1.x is deployed as an OAuth Resource Server, APM becomes a client application to When APM 13.0.0-13.1.x is deployed as an OAuth Resource Server, APM becomes a client application to an external OAuth authorization server. In certain cases when communication between the BIG-IP APM and the OAuth authorization server is lost, APM may not display the intended message in the failure response
nvd
CVE-2018-5505P4MEDIUMCVSS 5.9v13.1.0 - 13.1.0.32018-03-22
CVE-2018-5505 [MEDIUM] CVE-2018-5505: On F5 BIG-IP versions 13.1.0 - 13.1.0.3, when ASM and AVR are both provisioned, TMM may restart whil On F5 BIG-IP versions 13.1.0 - 13.1.0.3, when ASM and AVR are both provisioned, TMM may restart while processing DNS requests when the virtual server is configured with a DNS profile and the Protocol setting is set to TCP.
nvd
CVE-2018-15324P4MEDIUMCVSS 5.9v14.0.0-14.0.0.2, 13.0.0-13.1.1.12018-10-31
CVE-2018-15324 [MEDIUM] CWE-20 CVE-2018-15324: On BIG-IP APM 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1, TMM may restart when processing a specially crafte On BIG-IP APM 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1, TMM may restart when processing a specially crafted request with APM portal access.
nvd
CVE-2018-5526P4MEDIUMCVSS 6.5v13.1.0-13.1.0.52018-06-01
CVE-2018-5526 [MEDIUM] CVE-2018-5526: Under certain conditions, on F5 BIG-IP ASM 13.1.0-13.1.0.5, Behavioral DOS (BADOS) protection may fa Under certain conditions, on F5 BIG-IP ASM 13.1.0-13.1.0.5, Behavioral DOS (BADOS) protection may fail during an attack.
nvd
CVE-2019-6590P4MEDIUMCVSS 5.9v13.0.0-13.0.1, 12.1.0-12.1.3.62019-02-05
CVE-2019-6590 [MEDIUM] CVE-2019-6590: On BIG-IP LTM 13.0.0 to 13.0.1 and 12.1.0 to 12.1.3.6, under certain conditions, the TMM may consume On BIG-IP LTM 13.0.0 to 13.0.1 and 12.1.0 to 12.1.3.6, under certain conditions, the TMM may consume excessive resources when processing SSL Session ID Persistence traffic.
nvd
CVE-2018-5508P4MEDIUMCVSS 5.9v13.0.0v12.0.0-12.1.3.1+3 more2018-04-13
CVE-2018-5508 [MEDIUM] CVE-2018-5508: On F5 BIG-IP PEM versions 13.0.0, 12.0.0-12.1.3.1, 11.6.0-11.6.2, 11.5.1-11.5.5, or 11.2.1, under ce On F5 BIG-IP PEM versions 13.0.0, 12.0.0-12.1.3.1, 11.6.0-11.6.2, 11.5.1-11.5.5, or 11.2.1, under certain conditions, TMM may crash when processing compressed data though a Virtual Server with an associated PEM profile using the content insertion option.
nvd
CVE-2019-6595P4MEDIUMCVSS 6.1v11.5.x,11.6.x2019-02-26
CVE-2019-6595 [MEDIUM] CWE-79 CVE-2019-6595: Cross-site scripting (XSS) vulnerability in F5 BIG-IP Access Policy Manager (APM) 11.5.x and 11.6.x Cross-site scripting (XSS) vulnerability in F5 BIG-IP Access Policy Manager (APM) 11.5.x and 11.6.x Admin Web UI.
nvd