VendorsF5big-ip_advanced_web_application_firewallany version
Vulnerabilities

F5 Big-ip Advanced Web Application Firewall any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

188CVEs
CVE-2021-23027
On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, and 14.1.x before 14.1.4.3, a DOM based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to execute JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published 2021-09-14 · Modified
6.1EPSS 0.006
CVE-2024-33604
BIG-IP Configuration utility XSS vulnerability
Published 2024-05-08 · Analyzed
6.1EPSS 0.003
CVE-2023-3470
BIG-IP FIPS HSM password vulnerability CVE-2023-3470
Published 2023-08-02 · Modified
6.1EPSS 0.002
CVE-2020-5929
In versions 13.0.0-13.0.0 HF2, 12.1.0-12.1.2 HF1, and 11.6.1-11.6.2, BIG-IP platforms with Cavium Nitrox SSL hardware acceleration cards, a Virtual Server configured with a Client SSL profile, and using Anonymous (ADH) or Ephemeral (DHE) Diffie-Hellman key exchange and Single DH use option not enabled in the options list may be vulnerable to crafted SSL/TLS Handshakes that may result with a PMS (Pre-Master Secret) that starts in a 0 byte and may lead to a recovery of plaintext messages as BIG-IP TLS/SSL ADH/DHE sends different error messages acting as an oracle. Similar error messages when PMS starts with 0 byte coupled with very precise timing measurement observation may also expose this vulnerability.
Published 2020-09-25 · Modified
5.9EPSS 0.011
CVE-2024-28889
BIG-IP SSL vulnerability
Published 2024-05-08 · Analyzed
5.9EPSS 0.004
CVE-2021-22981
On all versions of BIG-IP 12.1.x and 11.6.x, the original TLS protocol includes a weakness in the master secret negotiation that is mitigated by the Extended Master Secret (EMS) extension defined in RFC 7627. TLS connections that do not use EMS are vulnerable to man-in-the-middle attacks during renegotiation. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Published 2021-02-12 · Modified
5.8EPSS 0.006
CVE-2023-43485
BIGIP and BIG-IQ TACACS+ audit log Vulnerability
Published 2023-10-10 · Modified
5.5EPSS 0.002
CVE-2023-38423
BIG-IP Configuration utility vulnerability
Published 2023-08-02 · Modified
5.4EPSS 0.003
CVE-2026-40703
BIG-IP Configuration utility CSRF vulnerability
Published 2026-05-13 · Analyzed
5.4EPSS 0.001
CVE-2021-22998
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, SYN flood protection thresholds are not enforced in secure network address translation (SNAT) listeners. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Published 2021-03-31 · Modified
5.3EPSS 0.009
CVE-2021-23053
On version 15.1.x before 15.1.3, 14.1.x before 14.1.3.1, and 13.1.x before 13.1.3.6, when the brute force protection feature of BIG-IP Advanced WAF or BIG-IP ASM is enabled on a virtual server and the virtual server is under brute force attack, the MySQL database may run out of disk space due to lack of row limit on undisclosed tables in the MYSQL database. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published 2021-09-14 · Modified
5.3EPSS 0.009
CVE-2022-23027
On BIG-IP versions 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, 13.1.x beginning in 13.1.3.6, 12.1.5.3-12.1.6, and 11.6.5.2, when a FastL4 profile and an HTTP, FIX, and/or hash persistence profile are configured on the same virtual server, undisclosed requests can cause the virtual server to stop processing new client connections. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published 2022-01-25 · Modified
5.3EPSS 0.009
CVE-2022-23030
On version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versions of 13.1.x, when the BIG-IP Virtual Edition (VE) uses the ixlv driver (which is used in SR-IOV mode and requires Intel X710/XL710/XXV710 family of network adapters on the Hypervisor) and TCP Segmentation Offload configuration is enabled, undisclosed requests may cause an increase in CPU resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published 2022-01-25 · Modified
5.3EPSS 0.009
CVE-2022-23029
On BIG-IP version 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x, 12.1.x, and 11.6.x, when a FastL4 profile is configured on a virtual server, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published 2022-01-25 · Modified
5.3EPSS 0.007
CVE-2024-41723
BIG-IP iControl REST vulnerability
Published 2024-08-14 · Analyzed
5.3EPSS 0.003
CVE-2026-42058
BIG-IP iControl REST vulnerability
Published 2026-05-13 · Analyzed
5.3EPSS 0.003
CVE-2022-23031
On BIG-IP FPS, ASM, and Advanced WAF versions 16.1.x before 16.1.1, 15.1.x before 15.1.4, and 14.1.x before 14.1.4.4, an XML External Entity (XXE) vulnerability exists in an undisclosed page of the F5 Advanced Web Application Firewall (Advanced WAF) and BIG-IP ASM Traffic Management User Interface (TMUI), also referred to as the Configuration utility, that allows an authenticated high-privileged attacker to read local files and force BIG-IP to send HTTP requests. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published 2022-01-25 · Modified
4.9EPSS 0.008
CVE-2024-27202
BIG-IP TMUI XSS vulnerability
Published 2024-05-08 · Analyzed
4.7EPSS 0.003
CVE-2023-45219
BIG-IP tmsh vulnerability
Published 2023-10-10 · Modified
4.4EPSS 0.002
CVE-2023-28406
BIG-IP Configuration utility vulnerability
Published 2023-05-03 · Modified
4.3EPSS 0.012
CVE-2022-23026
On BIG-IP ASM & Advanced WAF version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versions of 13.1.x and 12.1.x, an authenticated user with low privileges, such as a guest, can upload data using an undisclosed REST endpoint causing an increase in disk resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published 2022-01-25 · Modified
4.3EPSS 0.007
CVE-2020-5947
In versions 16.0.0-16.0.0.1 and 15.1.0-15.1.1, on specific BIG-IP platforms, attackers may be able to obtain TCP sequence numbers from the BIG-IP system that can be reused in future connections with the same source and destination port and IP numbers. Only these platforms are affected: BIG-IP 2000 series (C112), BIG-IP 4000 series (C113), BIG-IP i2000 series (C117), BIG-IP i4000 series (C115), BIG-IP Virtual Edition (VE).
Published 2020-11-19 · Modified
4.3EPSS 0.007
CVE-2021-23001
On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, the upload functionality in BIG-IP Advanced WAF and BIG-IP ASM allows an authenticated user to upload files to the BIG-IP system using a call to an undisclosed iControl REST endpoint. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Published 2021-03-31 · Modified
4.3EPSS 0.006
CVE-2023-38419
BIG-IP and BIG-IQ iControl SOAP vulnerability
Published 2023-08-02 · Modified
4.3EPSS 0.005
CVE-2026-20732
BIG-IP Configuration utility vulnerability
Published 2026-02-04 · Analyzed
4.3EPSS 0.002
CVE-2024-23603
BIG-IP Advanced WAF and ASM Configuration utility vulnerability
Published 2024-02-14 · Analyzed
3.8EPSS 0.003
CVE-2022-41983
BIG-IP TMM Vulnerability CVE-2022-41983
Published 2022-10-19 · Modified
3.7EPSS 0.003
CVE-2026-63020
BIG-IP Configuration utility vulnerability
Published 2026-09-02 · Analyzed
3.1EPSS 0.002
← Prev5 / 5