VendorsF5big-ip_advanced_firewall_managerall versions
Vulnerabilities

F5 Big-ip Advanced Firewall Manager

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

551CVEs
CVE-2025-24312
BIG-IP AFM vulnerability
Published 2025-02-05 · Analyzed
8.7EPSS 0.004
CVE-2025-59481
BIG-IP iControl REST and tmsh vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.004
CVE-2025-61958
BIG-IP TMSH vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.004
CVE-2025-58071
BIG-IP IPSec vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.004
CVE-2025-59478
BIG-IP AFM DoS protection profile vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.004
CVE-2025-53474
BIG-IP iRules vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.003
CVE-2025-61990
TMM vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.003
CVE-2025-59781
BIG-IP DNS cache vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.003
CVE-2025-53856
TMM vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.003
CVE-2025-52585
BIG-IP Client SSL profile vulnerability
Published 2025-08-13 · Analyzed
8.7EPSS 0.003
CVE-2026-40618
BIG-IP SSL/TLS vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.003
CVE-2026-40629
BIG-IP SSL/TLS vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.003
CVE-2026-39455
BIG-IP Configuration utility vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.003
CVE-2026-41218
BIG-IP PEM iRules vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.003
CVE-2026-40423
BIG-IP SIP profile vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.003
CVE-2026-39458
BIG-IP DNS Cache vulnerability
Published 2026-05-13 · Modified
8.7EPSS 0.003
CVE-2026-42409
BIG-IP HTTP/2 vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.003
CVE-2026-42920
BIG-IP DTLS Vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.003
CVE-2026-41956
BIG-IP TMM Vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.003
CVE-2026-41953
BIG-IP Privilege Escalation vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.002
CVE-2026-40631
BIG-IP iControl SOAP vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.002
CVE-2026-42924
BIG-IP iControl SOAP vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.002
CVE-2025-61951
BIG-IP DTLS 1.2 Vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.002
CVE-2026-40698
iControl REST and TMSH vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.002
CVE-2026-32673
BIG-IP scripted monitor vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.002
CVE-2026-32643
BIG-IP and BIG-IQ privilege escalation vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.002
CVE-2026-42406
BIG-IP and BIG-IQ privilege escalation vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.002
CVE-2024-45844
BIG-IP monitors vulnerability
Published 2024-10-16 · Analyzed
8.6EPSS 0.106
CVE-2026-39459
iControl REST and tmsh vulnerability
Published 2026-05-13 · Analyzed
8.6EPSS 0.003
CVE-2023-22374
iControl SOAP vulnerability
Published 2023-02-01 · Modified
8.5EPSS 0.726
CVE-2015-8022
The Configuration utility in F5 BIG-IP LTM, Analytics, APM, ASM, GTM, and Link Controller 11.x before 11.2.1 HF16, 11.3.x, 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, and 11.6.x before 11.6.1; BIG-IP AAM 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, and 11.6.x before 11.6.1; BIG-IP AFM and PEM 11.3.x, 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, and 11.6.x before 11.6.1; BIG-IP Edge Gateway, WebAccelerator, and WOM 11.x before 11.2.1 HF16 and 11.3.0; and BIG-IP PSM 11.x before 11.2.1 HF16, 11.3.x, and 11.4.x before 11.4.1 HF10 allows remote authenticated users with certain permissions to gain privileges by leveraging an Access Policy Manager customization configuration section that allows file uploads.
Published 2016-08-19 · Modified
8.5EPSS 0.027
CVE-2020-5945
In BIG-IP versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.2.7, undisclosed TMUI page contains a stored cross site scripting vulnerability (XSS). The issue allows a minor privilege escalation for resource admin to escalate to full admin.
Published 2020-11-05 · Modified
8.5EPSS 0.013
CVE-2017-6167
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM and WebSafe software version 13.0.0 and 12.1.0 - 12.1.2, race conditions in iControl REST may lead to commands being executed with different privilege levels than expected.
Published 2017-12-21 · Modified
8.5EPSS 0.011
CVE-2019-6636
On BIG-IP (AFM, ASM) 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, and 11.5.1-11.6.4, a stored cross-site scripting vulnerability in AFM feed list. In the worst case, an attacker can store a CSRF which results in code execution as the admin user. The level of user role which can perform this attack are resource administrator and administrator.
Published 2019-07-03 · Modified
8.5EPSS 0.009
CVE-2025-59483
BIG-IP Configuration utility and tmsh vulnerability
Published 2025-10-15 · Analyzed
8.5EPSS 0.004
CVE-2025-59269
BIG-IP Configuration utility XSS vulnerability
Published 2025-10-15 · Analyzed
8.4EPSS 0.003
CVE-2021-22978
On BIG-IP version 16.0.x before 16.0.1, 15.1.x before 15.1.1, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.5, and all 12.1.x and 11.6.x versions, undisclosed endpoints in iControl REST allow for a reflected XSS attack, which could lead to a complete compromise of BIG-IP if the victim user is granted the admin role. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Published 2021-02-12 · Modified
8.3EPSS 0.008
CVE-2026-41217
BIG-IP tmsh vulnerability
Published 2026-05-13 · Analyzed
8.3EPSS 0.001
CVE-2024-41164
BIG-IP MPTCP vulnerability
Published 2024-08-14 · Analyzed
8.2EPSS 0.004
CVE-2025-58096
BIG-IP TMM vulnerability
Published 2025-10-15 · Analyzed
8.2EPSS 0.003
← Prev3 / 14Next →