CVEs (524)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1F5 19Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+16 moreJun 17, 2026 Oct 10, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 When TACACS+ audit forwarding is configured on BIG-IP or BIG-IQ system, sharedsecret is logged in plaintext in the audit log. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated...Show more |
1F5 19Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+16 moreJun 17, 2026 Oct 10, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 When a non-admin user has been assigned an administrator role via an iControl REST PUT request and later the user's role is reverted back to a non-admin role via the Configuration utility, tmsh, or iControl REST. BIG-IP...Show more |
1F5 20Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+17 moreJun 17, 2026 Oct 10, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2
The BIG-IP and BIG-IQ systems do not encrypt some sensitive information written to Database (DB) variables.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. |
1F5 18Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+15 moreJun 17, 2026 Oct 10, 2023 N/A· v4 9.9 CRITICAL· v3 N/A· v2 A directory traversal vulnerability exists in the BIG-IP Configuration Utility that may allow an authenticated attacker to execute commands on the BIG-IP system. For BIG-IP system running in Appliance mode, a successful...Show more |
1F5 19Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+16 moreJun 17, 2026 Oct 10, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2
When IPSec is configured on a Virtual Server, undisclosed traffic can cause TMM to terminate.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
|
1F5 19Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+16 moreJun 17, 2026 Oct 10, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 When TCP Verified Accept is enabled on a TCP profile that is configured on a Virtual Server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of T...Show more |
1F5 18Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+15 moreJun 17, 2026 Oct 10, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 An authenticated user's session cookie may remain valid for a limited time after logging out from the BIG-IP Configuration utility on a multi-blade VIPRION platform. Note: Software versions which have reached End of T...Show more |
1F5 20Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+17 moreJun 17, 2026 Oct 10, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 When a client-side HTTP/2 profile and the HTTP MRF Router option are enabled for a virtual server, and an iRule using the HTTP_REQUEST event or Local Traffic Policy are associated with the virtual server, undisclosed req...Show more |
1F5 30Big Ip 10200v F Firmware Big Ip 10350v F FirmwareBig Ip 11000 F Firmware+27 moreJun 17, 2026 Aug 2, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Specific F5 BIG-IP platforms with Cavium Nitrox FIPS HSM cards generate a deterministic password for the Crypto User account. The predictable nature of the password allows an authenticated user with TMSH access to the...Show more |
1F5 19Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+16 moreJun 17, 2026 Aug 2, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 A cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software vers...Show more |
1F5 20Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+17 moreJun 17, 2026 Aug 2, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 An authenticated attacker with guest privileges or higher can cause the iControl SOAP process to terminate by sending undisclosed requests. Note: Software versions which have reached End of Technical Support (EoTS) are...Show more |
1F5 19Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+16 moreJun 17, 2026 Aug 2, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which allows an attacker to run JavaScript in the context of the currently logged-in user. Note: So...Show more |
1F5 19Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+16 moreJun 17, 2026 May 3, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 When UDP profile with idle timeout set to immediate or the value 0 is configured on a virtual server, undisclosed traffic can cause TMM to terminate. Note: Software versions which have reached End of Technical Support...Show more |
1F5 19Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+16 moreJun 17, 2026 May 3, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 A directory traversal vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which may allow an authenticated attacker to read files with .xml extension. Access to restricted information is limit...Show more |
1F5 19Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+16 moreJun 17, 2026 May 3, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Multiple reflected cross-site scripting (XSS) vulnerabilities exist in undisclosed pages of the BIG-IP Configuration utility which allow an attacker to run JavaScript in the context of the currently logged-in user. Not...Show more |
1F5 20Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+17 moreJun 17, 2026 May 3, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 When an SSL profile is configured on a Virtual Server, undisclosed traffic can cause an increase in CPU or SSL accelerator resource utilization. Note: Software versions which have reached End of Technical Support (Eo...Show more |
1F5 13Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+10 moreJun 17, 2026 Feb 1, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 On BIG-IP Virtual Edition versions 15.1x beginning in 15.1.4 to before 15.1.8 and 14.1.x beginning in 14.1.5 to before 14.1.5.3, and BIG-IP SPK beginning in 1.5.0 to before 1.6.0, when FastL4 profile is configured on a v...Show more |
1F5 12Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+9 moreJun 17, 2026 Feb 1, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 On BIG-IP versions 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a SIP profile is configured on a Message Routing type virtual server, undisclosed traffic can ca...Show more |
1F5 13Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+10 moreJun 17, 2026 Feb 1, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 On BIG-IP versions 17.0.x before 17.0.0.2 and 16.1.x before 16.1.3.3, and BIG-IP SPK starting in version 1.6.0, when a client-side HTTP/2 profile and the HTTP MRF Router option are enabled for a virtual server, undisclos...Show more |
1F5 12Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+9 moreJun 17, 2026 Feb 1, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 On BIG-IP versions 17.0.x before 17.0.0.2 and 16.1.x before 16.1.3.3, when a HTTP profile with the non-default Enforcement options of Enforce HTTP Compliance and Unknown Methods: Reject are configured on a virtual server...Show more |