VendorsF5big-ip_advanced_firewall_managerall versions
Vulnerabilities

F5 Big-ip Advanced Firewall Manager

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

551CVEs
CVE-2021-22990
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, on systems with Advanced WAF or BIG-IP ASM provisioned, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has an authenticated remote command execution vulnerability in undisclosed pages. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Published 2021-03-31 · Modified
9.0EPSS 0.088
CVE-2012-3163
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Information Schema.
Published 2012-10-17 · Modified
9.0EPSS 0.051
CVE-2015-7394
The datastor kernel module in F5 BIG-IP Analytics, APM, ASM, Link Controller, and LTM 11.1.0 before 12.0.0, BIG-IP AAM 11.4.0 before 12.0.0, BIG-IP AFM, PEM 11.3.0 before 12.0.0, BIG-IP Edge Gateway, WebAccelerator, and WOM 11.1.0 through 11.3.0, BIG-IP GTM 11.1.0 through 11.6.0, BIG-IP PSM 11.1.0 through 11.4.1, BIG-IQ Cloud and Security 4.0.0 through 4.5.0, BIG-IQ Device 4.2.0 through 4.5.0, BIG-IQ ADC 4.5.0, and Enterprise Manager 3.0.0 through 3.1.1 allows remote authenticated users to cause a denial of service or gain privileges by leveraging permission to upload and execute code.
Published 2015-11-06 · Modified
9.0EPSS 0.039
CVE-2016-5020
F5 BIG-IP before 12.0.0 HF3 allows remote authenticated users to modify the account configuration of users with the Resource Administration role and gain privilege via a crafted external Extended Application Verification (EAV) monitor script.
Published 2016-06-30 · Modified
9.0EPSS 0.034
CVE-2019-6642
In BIG-IP 15.0.0, 14.0.0-14.1.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.2, and 11.5.2-11.6.4, BIG-IQ 6.0.0-6.1.0 and 5.1.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1, authenticated users with the ability to upload files (via scp, for example) can escalate their privileges to allow root shell access from within the TMOS Shell (tmsh) interface. The tmsh interface allows users to execute a secondary program via tools like sftp or scp.
Published 2019-07-01 · Modified
9.0EPSS 0.018
CVE-2021-23038
On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x, a stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to execute JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published 2021-09-14 · Modified
9.0EPSS 0.009
CVE-2025-20058
BIG-IP message routing vulnerability
Published 2025-02-05 · Analyzed
8.9EPSS 0.004
CVE-2025-21087
TMM Vulnerability
Published 2025-02-05 · Analyzed
8.9EPSS 0.004
CVE-2022-41622
iControl SOAP vulnerability
Published 2022-12-07 · Modified
8.8EPSS 0.923
CVE-2025-20029
BIG-IP iControl REST and tmsh vulnerability
Published 2025-02-05 · Analyzed
8.8EPSS 0.072
CVE-2023-46748
BIG-IP Configuration utility authenticated SQL injection vulnerability
Published 2023-10-26 · Analyzed
8.8KEVEPSS 0.045
CVE-2021-23025
On version 15.1.x before 15.1.0.5, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.5, and all versions of 12.1.x and 11.6.x, an authenticated remote command execution vulnerability exists in the BIG-IP Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published 2021-09-14 · Modified
8.8EPSS 0.023
CVE-2016-9251
In F5 BIG-IP 12.0.0 through 12.1.2, an authenticated attacker may be able to cause an escalation of privileges through a crafted iControl REST connection.
Published 2017-05-09 · Modified
8.8EPSS 0.015
CVE-2019-6646
On BIG-IP 11.5.2-11.6.4 and Enterprise Manager 3.1.1, REST users with guest privileges may be able to escalate their privileges and run commands with admin privileges.
Published 2019-09-04 · Modified
8.8EPSS 0.015
CVE-2021-23040
On BIG-IP AFM version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x, a SQL injection vulnerability exists in an undisclosed page of the BIG-IP Configuration utility. This issue is exposed only when BIG-IP AFM is provisioned. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published 2021-09-14 · Modified
8.8EPSS 0.010
CVE-2022-28716
On 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x 11.6.x, a DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP AFM, CGNAT, and PEM Configuration utility that allows an attacker to execute JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Published 2022-05-05 · Modified
8.8EPSS 0.008
CVE-2020-5904
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, a cross-site request forgery (CSRF) vulnerability in the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, exists in an undisclosed page.
Published 2020-07-01 · Modified
8.8EPSS 0.006
CVE-2026-41957
BIG-IP and BIG-IQ Configuration utility vulnerability
Published 2026-05-13 · Analyzed
8.8EPSS 0.005
CVE-2021-23026
BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x and 11.6.x and all versions of BIG-IQ 8.x, 7.x, and 6.x are vulnerable to cross-site request forgery (CSRF) attacks through iControl SOAP. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published 2021-09-14 · Modified
8.8EPSS 0.005
CVE-2022-41800
Appliance mode iControl REST vulnerability
Published 2022-12-07 · Modified
8.7EPSS 0.769
CVE-2025-31644
Appliance mode BIG-IP iControl REST and tmsh vulnerability
Published 2025-05-07 · Analyzed
8.7EPSS 0.265
CVE-2024-22093
Appliance mode iControl REST vulnerability
Published 2024-02-14 · Analyzed
8.7EPSS 0.008
CVE-2025-23239
BIG-IP iControl REST vulnerability
Published 2025-02-05 · Analyzed
8.7EPSS 0.008
CVE-2026-34176
Knowledge Appliance mode iControl REST vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.007
CVE-2024-41727
BIG-IP TMM vulnerability
Published 2024-08-14 · Analyzed
8.7EPSS 0.005
CVE-2024-39778
BIG-IP HSB vulnerability
Published 2024-08-14 · Analyzed
8.7EPSS 0.005
CVE-2026-42930
Appliance mode iControl REST vulnerability
Published 2026-05-13 · Undergoing Analysis
8.7EPSS 0.005
CVE-2025-21091
BIG-IP SNMP vulnerability
Published 2025-02-05 · Analyzed
8.7EPSS 0.005
CVE-2025-48008
BIG-IP MPTCP vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.004
CVE-2025-53868
BIG-IP SCP and SFTP vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.004
CVE-2023-43746
BIG-IP Appliance mode external monitor vulnerability
Published 2023-10-10 · Modified
8.7EPSS 0.004
CVE-2025-46706
BIG-IP iRules vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.004
CVE-2025-36504
BIG-IP HTTP/2 vulnerability
Published 2025-05-07 · Analyzed
8.7EPSS 0.004
CVE-2025-41431
TMM Vulnerability
Published 2025-05-07 · Analyzed
8.7EPSS 0.004
CVE-2025-41433
BIG-IP SIP ALG profile vulnerability
Published 2025-05-07 · Analyzed
8.7EPSS 0.004
CVE-2025-41399
SCTP Vulnerability
Published 2025-05-07 · Analyzed
8.7EPSS 0.004
CVE-2025-41414
BIG-IP HTTP/2 vulnerability
Published 2025-05-07 · Analyzed
8.7EPSS 0.004
CVE-2025-36557
BIG-IP HTTP vulnerability
Published 2025-05-07 · Analyzed
8.7EPSS 0.004
CVE-2025-20045
BIG-IP SIP MRF Vulnerability
Published 2025-02-05 · Analyzed
8.7EPSS 0.004
CVE-2025-22846
BIG-IP SIP Vulnerability
Published 2025-02-05 · Analyzed
8.7EPSS 0.004
← Prev2 / 14Next →