cbcvebase.

F5 Networks Inc Big-Ip vulnerabilities

26 known vulnerabilities affecting f5_networks_inc/big-ip.

Total CVEs
26
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH13MEDIUM12LOW1

Vulnerabilities

Page 2 of 2
CVE-2018-5528P4MEDIUMCVSS 5.3v13.1.0.4-13.1.0.7, 13.0.12018-06-27
CVE-2018-5528 [MEDIUM] CWE-20 CVE-2018-5528: Under certain conditions, TMM may restart and produce a core file while processing APM data on BIG-I Under certain conditions, TMM may restart and produce a core file while processing APM data on BIG-IP 13.0.1 or 13.1.0.4-13.1.0.7.
nvd
CVE-2019-6591P4MEDIUMCVSS 5.4v14.0.0-14.0.0.4, 13.0.0-13.1.1.3, 12.1.0-12.1.3.72019-02-05
CVE-2019-6591 [MEDIUM] CWE-79 CVE-2019-6591: On BIG-IP APM 14.0.0 to 14.0.0.4, 13.0.0 to 13.1.1.3 and 12.1.0 to 12.1.3.7, a reflected cross-site On BIG-IP APM 14.0.0 to 14.0.0.4, 13.0.0 to 13.1.1.3 and 12.1.0 to 12.1.3.7, a reflected cross-site scripting (XSS) vulnerability exists in the resource information page for authenticated users when a full webtop is configured on the BIG-IP APM system.
nvd
CVE-2019-6601P4MEDIUMCVSS 5.5v13.0.0, 12.1.0-12.1.3.7, 11.6.1-11.6.3.2, 11.5.1-11.5.82019-03-13
CVE-2019-6601 [MEDIUM] CWE-269 CVE-2019-6601: In BIG-IP 13.0.0, 12.1.0-12.1.3.7, 11.6.1-11.6.3.2, or 11.5.1-11.5.8, the Application Acceleration M In BIG-IP 13.0.0, 12.1.0-12.1.3.7, 11.6.1-11.6.3.2, or 11.5.1-11.5.8, the Application Acceleration Manager (AAM) wamd process used in processing of images and PDFs fails to drop group permissions when executing helper scripts.
nvd
CVE-2018-15316P4MEDIUMCVSS 5.5v13.0.0-13.1.1.12018-10-19
CVE-2018-15316 [MEDIUM] CVE-2018-15316: In F5 BIG-IP APM 13.0.0-13.1.1.1, APM Client 7.1.5-7.1.6, and/or Edge Client 7101-7160, the BIG-IP A In F5 BIG-IP APM 13.0.0-13.1.1.1, APM Client 7.1.5-7.1.6, and/or Edge Client 7101-7160, the BIG-IP APM Edge Client component loads the policy library with user permission and bypassing the endpoint checks.
nvd
CVE-2018-15334P4MEDIUMCVSS 4.3vAll versions 11.2.1+2018-12-28
CVE-2018-15334 [MEDIUM] CWE-352 CVE-2018-15334: A cross-site request forgery (CSRF) vulnerability in the APM webtop 11.2.1 or greater may allow atta A cross-site request forgery (CSRF) vulnerability in the APM webtop 11.2.1 or greater may allow attacker to force an APM webtop session to log out and require re-authentication.
nvd
CVE-2018-5538P4LOWCVSS 3.7v13.1.0-13.1.0.7v12.1.3-12.1.3.52018-07-25
CVE-2018-5538 [LOW] CVE-2018-5538: On F5 BIG-IP DNS 13.1.0-13.1.0.7, 12.1.3-12.1.3.5, DNS Express / DNS Zones accept NOTIFY messages on On F5 BIG-IP DNS 13.1.0-13.1.0.7, 12.1.3-12.1.3.5, DNS Express / DNS Zones accept NOTIFY messages on the management interface from source IP addresses not listed in the 'Allow NOTIFY From' configuration parameter when the db variable "dnsexpress.notifyport" is set to any value other than the default of "0".
nvd
F5 Networks Inc Big-Ip vulnerabilities | cvebase