CVEs (12)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1F5 26Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+23 moreJun 17, 2026 Aug 13, 2025 6.9 MEDIUM· v4 5.3 MEDIUM· v3 N/A· v2 An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit (HTTP/2 MadeYouReset Attack). Note: Software versions which ha...Show more |
1F5 24Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+21 moreJun 17, 2026 May 7, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 When a Stream Control Transmission Protocol (SCTP) profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of T...Show more |
1F5 24Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+21 moreJun 17, 2026 May 7, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 When a BIG-IP HTTP/2 httprouter profile is configured on a virtual server, undisclosed responses can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support...Show more |
1F5 1Big Ip Next Central Manager Jun 17, 2026 Feb 5, 2025 7.1 HIGH· v4 6.5 MEDIUM· v3 N/A· v2 When BIG-IP Next Central Manager is running, undisclosed requests to the BIG-IP Next Central Manager API can cause the BIG-IP Next Central Manager Node's Kubernetes service to terminate. Note: Software versions wh...Show more |
1F5 1Big Ip Next Central Manager Jun 17, 2026 Feb 5, 2025 6.7 MEDIUM· v4 4.4 MEDIUM· v3 N/A· v2 When users log in through the webUI or API using local authentication, BIG-IP Next Central Manager may log sensitive information in the pgaudit log files. Note: Software versions which have reached End of Technical Su...Show more |
1F5 1Big Ip Next Central Manager Jun 17, 2026 Aug 14, 2024 5.1 MEDIUM· v4 5.5 MEDIUM· v3 N/A· v2 When generating QKView of BIG-IP Next instance from the BIG-IP Next Central Manager (CM), F5 iHealth credentials will be logged in the BIG-IP Central Manager logs. Note: Software versions which have reached End of Tech...Show more |
1F5 1Big Ip Next Central Manager Jun 17, 2026 Aug 14, 2024 8.9 HIGH· v4 8.8 HIGH· v3 N/A· v2 The Central Manager user session refresh token does not expire when a user logs out. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated |
1F5 1Big Ip Next Central Manager Jun 17, 2026 Aug 14, 2024 6.3 MEDIUM· v4 5.3 MEDIUM· v3 N/A· v2 BIG-IP Next Central Manager may allow an attacker to lock out an account that has never been logged in. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. |
An improper certificate validation vulnerability exists in BIG-IP Next Central Manager and may allow an attacker to impersonate an Instance Provider system. Note: Software versions which have reached End of Technical Su...Show more |
BIG-IP Next Central Manager (CM) may allow an unauthenticated, remote attacker to obtain the BIG-IP Next LTM/WAF instance credentials. Note: Software versions which have reached End of Technical Support (EoTS) are not...Show more |
An SQL injection vulnerability exists in the BIG-IP Next Central Manager API (URI). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated |
An OData injection vulnerability exists in the BIG-IP Next Central Manager API (URI). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. |