F5
f5
1,032 CVEs • 284 products
Products (284)
Click to collapseToggle
Products (284)
Click to collapse
CVEs (1,032)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1F5 1Big Ip Next Central Manager Jun 17, 2026 Feb 5, 2025 7.1 HIGH· v4 6.5 MEDIUM· v3 N/A· v2 When BIG-IP Next Central Manager is running, undisclosed requests to the BIG-IP Next Central Manager API can cause the BIG-IP Next Central Manager Node's Kubernetes service to terminate. Note: Software versions wh...Show more |
1F5 2Big Ip Advanced Firewall Manager Big Ip Next Cloud Native Network FunctionsJun 17, 2026 Feb 5, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 When BIG-IP AFM is provisioned with IPS module enabled and protocol inspection profile is configured on a virtual server or firewall rule or policy, undisclosed traffic can cause an increase in CPU resource utilization....Show more |
2Debian F53Debian Linux NginxNginx PlusJun 17, 2026 Feb 5, 2025 5.3 MEDIUM· v4 4.3 MEDIUM· v3 N/A· v2 When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. This vulnerability arise...Show more |
An insufficient verification of data authenticity vulnerability exists in BIG-IP APM Access Policy endpoint inspection that may allow an attacker to bypass endpoint inspection checks for VPN connection initiated thru BIG...Show more |
1F5 1Big Ip Next Central Manager Jun 17, 2026 Feb 5, 2025 6.7 MEDIUM· v4 4.4 MEDIUM· v3 N/A· v2 When users log in through the webUI or API using local authentication, BIG-IP Next Central Manager may log sensitive information in the pgaudit log files. Note: Software versions which have reached End of Technical Su...Show more |
1F5 1Big Ip Access Policy Manager Jun 17, 2026 Feb 5, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 When BIG-IP APM Access Profile is configured on a virtual server, undisclosed request can cause TMM to terminate.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. |
1F5 11Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+8 moreJun 17, 2026 Feb 5, 2025 8.5 HIGH· v4 8.7 HIGH· v3 N/A· v2 When running in Appliance mode, and logged into a highly-privileged role, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful exploit can allow the attack...Show more |
1F5 1Big Ip Policy Enforcement Manager Jun 17, 2026 Feb 5, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 When BIG-IP PEM Control Plane listener Virtual Server is configured with Diameter Endpoint profile, undisclosed traffic can cause the Virtual Server to stop processing new client connections and an increase in memory res...Show more |
1F5 12Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+9 moreJun 17, 2026 Feb 5, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 When SIP Session and Router ALG profiles are configured on a Message Routing type virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which ha...Show more |
1F5 21Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+18 moreJun 17, 2026 Feb 5, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 When SNMP v1 or v2c are disabled on the BIG-IP, undisclosed requests can cause an increase in memory resource utilization.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated |
1F5 21Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+18 moreJun 17, 2026 Feb 5, 2025 8.9 HIGH· v4 7.5 HIGH· v3 N/A· v2 When Client or Server SSL profiles are configured on a Virtual Server, or DNSSEC signing operations are in use, undisclosed traffic can cause an increase in memory and CPU resource utilization. Note: Software versio...Show more |
1F5 21Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+18 moreJun 17, 2026 Feb 5, 2025 8.9 HIGH· v4 7.5 HIGH· v3 N/A· v2 When a BIG-IP message routing profile is configured on a virtual server, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS...Show more |
1F5 21Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+18 moreJun 17, 2026 Feb 5, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 When SIP session Application Level Gateway mode (ALG) profile with Passthru Mode enabled and SIP router ALG profile are configured on a Message Routing type virtual server, undisclosed traffic can cause the Traffic Manag...Show more |
1F5 21Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+18 moreJun 17, 2026 Feb 5, 2025 8.7 HIGH· v4 8.8 HIGH· v3 N/A· v2 Command injection vulnerability exists in iControl REST and BIG-IP TMOS Shell (tmsh) save command, which may allow an authenticated attacker to execute arbitrary system commands. Note: Software versions which have r...Show more |
1F5 4Nginx Api Connectivity Manager Nginx Ingress ControllerNginx Instance Manager+1 moreJun 17, 2026 Nov 6, 2024 5.1 MEDIUM· v4 5.4 MEDIUM· v3 N/A· v2 A session fixation issue was discovered in the NGINX OpenID Connect reference implementation, where a nonce was not checked at login time. This flaw allows an attacker to fix a victim's session to an attacker-controlled...Show more |
1F5 1Big Iq Centralized Management Jun 17, 2026 Oct 16, 2024 4.8 MEDIUM· v4 6.8 MEDIUM· v3 N/A· v2 A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IQ Configuration utility that allows an attacker with the Administrator role to run JavaScript in the context of the currently lo...Show more |
1F5 21Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+18 moreJun 17, 2026 Oct 16, 2024 8.6 HIGH· v4 7.2 HIGH· v3 N/A· v2 BIG-IP monitor functionality may allow an attacker to bypass access control restrictions, regardless of the port lockdown settings. Note: Software versions which have reached End of Technical Support (EoTS) are not eval...Show more |
1F5 2Nginx Agent Nginx Instance ManagerJun 17, 2026 Aug 22, 2024 6.9 MEDIUM· v4 4.9 MEDIUM· v3 N/A· v2 NGINX Agent's "config_dirs" restriction feature allows a highly privileged attacker to gain the ability to write/overwrite files outside of the designated secure directory. |
1F5 2Nginx Open Source Nginx PlusJun 17, 2026 Aug 14, 2024 5.7 MEDIUM· v4 4.7 MEDIUM· v3 N/A· v2 NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module, which might allow an attacker to over-read NGINX worker memory resulting in its termination, using a specially crafted mp4 file. The issue...Show more |
1F5 21Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+18 moreJun 17, 2026 Aug 14, 2024 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 In BIG-IP tenants running on r2000 and r4000 series hardware, or BIG-IP Virtual Edition (VEs) using Intel E810 SR-IOV NIC, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versi...Show more |