F5
f5
1,032 CVEs • 284 products
Products (284)
Click to collapseToggle
Products (284)
Click to collapse
CVEs (1,032)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1F5 21Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+18 moreJun 17, 2026 Oct 15, 2025 8.2 HIGH· v4 7.5 HIGH· v3 N/A· v2 When the database variable tm.tcpudptxchecksum is configured as non-default value Software-only on a BIG-IP system, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software ver...Show more |
1F5 3Big Ip Next Cloud Native Network Functions Big Ip Next For KubernetesBig Ip Next Service Proxy For KubernetesJun 17, 2026 Oct 15, 2025 7.1 HIGH· v4 6.5 MEDIUM· v3 N/A· v2 On BIG-IP Next CNF, BIG-IP Next SPK, and BIG-IP Next for Kubernetes systems, repeated undisclosed API calls can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End...Show more |
1F5 1Big Ip Application Security Manager Jun 17, 2026 Oct 15, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 When the BIG-IP Advanced WAF and ASM security policy and a server-side HTTP/2 profile are configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Softwa...Show more |
When BIG-IP SSL Orchestrator explicit forward proxy is configured on a virtual server and the proxy connect feature is enabled, undisclosed traffic may cause memory corruption. Note: Software versions which have reached...Show more |
1F5 2Big Ip Advanced Web Application Firewall Big Ip Application Security ManagerJun 17, 2026 Oct 15, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 When a BIG-IP Advanced WAF or BIG-IP ASM Security Policy is configured with a JSON content profile that has a malformed JSON schema, and the security policy is applied to a virtual server, undisclosed requests can cause...Show more |
1F5 1Big Ip Access Policy Manager Jun 17, 2026 Oct 15, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 When a BIG-IP APM OAuth access profile (Resource Server or Resource Client) is configured on a virtual server, undisclosed traffic can cause the apmd process to terminate. Note: Software versions which have reached End...Show more |
1F5 3Big Ip Next Cloud Native Network Functions Big Ip Next For KubernetesBig Ip Next Service Proxy For KubernetesJun 17, 2026 Oct 15, 2025 6.0 MEDIUM· v4 6.5 MEDIUM· v3 N/A· v2 When an iRule is configured on a virtual server via the declarative API, upon re-instantiation, the cleanup process can cause an increase in the Traffic Management Microkernel (TMM) memory resource utilization. Note: So...Show more |
1F5 21Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+18 moreJun 17, 2026 Oct 15, 2025 6.9 MEDIUM· v4 4.9 MEDIUM· v3 N/A· v2 A directory traversal vulnerability exists in TMUI that allows a highly privileged authenticated attacker to access files which are not limited to the intended files. Note: Software versions which have reached End of Te...Show more |
1F5 3Big Ip Next Cloud Native Network Functions Big Ip Next For KubernetesBig Ip Policy Enforcement ManagerJun 17, 2026 Oct 15, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 When a classification profile is configured on a virtual server without an HTTP or HTTP/2 profile, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have...Show more |
1F5 21Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+18 moreJun 17, 2026 Oct 15, 2025 8.5 HIGH· v4 8.7 HIGH· v3 N/A· v2 When running in Appliance mode, a highly privileged authenticated attacker with access to SCP and SFTP may be able to bypass Appliance mode restrictions using undisclosed commands. Note: Software versions which have rea...Show more |
1F5 21Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+18 moreJun 17, 2026 Oct 15, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 When a virtual server, network address translation (NAT) object, or secure network address translation (SNAT) object uses the embedded Packet Velocity Acceleration (ePVA) feature, undisclosed traffic can cause the Traffi...Show more |
1F5 21Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+18 moreJun 17, 2026 Oct 15, 2025 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Note: Software versions which have reached End of Technical Support (EoTS) are not...Show more |
1F5 21Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+18 moreJun 17, 2026 Oct 15, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 When an iRule using an ILX::call command is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technica...Show more |
1F5 23Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+20 moreJun 17, 2026 Oct 15, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 When a TCP profile with Multipath TCP (MPTCP) enabled is configured on a virtual server, undisclosed traffic along with conditions beyond the attacker's control can cause the Traffic Management Microkernel (TMM) to termi...Show more |
When SNMP is configured on F5OS Appliance and Chassis systems, undisclosed requests can cause an increase in SNMP memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) a...Show more |
1F5 2Big Ip Access Policy Manager Big Ip Ssl OrchestratorJun 17, 2026 Oct 15, 2025 7.1 HIGH· v4 6.5 MEDIUM· v3 N/A· v2 When the BIG-IP system is configured as both a Security Assertion Markup Language (SAML) service provider (SP) and Identity Provider (IdP), with single logout (SLO) enabled on an access policy, undisclosed requests can c...Show more |
1F5 23Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+20 moreJun 17, 2026 Oct 15, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 When an iRule containing the HTTP::respond command is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical...Show more |
When BIG-IP SSL Orchestrator is enabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluate...Show more |
F5 Access for Android before version 3.1.2 which uses HTTPS does not verify the remote endpoint identity.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. |
1F5 26Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+23 moreJun 17, 2026 Aug 13, 2025 6.9 MEDIUM· v4 5.3 MEDIUM· v3 N/A· v2 An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit (HTTP/2 MadeYouReset Attack). Note: Software versions which ha...Show more |