VendorsF5big-ip_analyticsall versions
Vulnerabilities

F5 Big-ip Analytics

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

510CVEs
CVE-2019-6597
In BIG-IP 13.0.0-13.1.1.1, 12.1.0-12.1.3.7, 11.6.1-11.6.3.2, or 11.5.1-11.5.8 or Enterprise Manager 3.1.1, when authenticated administrative users run commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, restrictions on allowed commands may not be enforced.
Published 2019-03-13 · Modified
7.2EPSS 0.013
CVE-2018-15327
In BIG-IP 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1 or Enterprise Manager 3.1.1, when authenticated administrative users run commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, restrictions on allowed commands may not be enforced.
Published 2018-10-31 · Modified
7.2EPSS 0.012
CVE-2018-15329
On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.1, or 12.1.0-12.1.3.7, or Enterprise Manager 3.1.1, when authenticated administrative users run commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, restrictions on allowed commands may not be enforced.
Published 2018-12-20 · Modified
7.2EPSS 0.012
CVE-2022-35735
BIG-IP monitor configuration vulnerability CVE-2022-35735
Published 2022-08-04 · Modified
7.2EPSS 0.009
CVE-2023-42768
BIG-IP iControl REST vulnerability
Published 2023-10-10 · Modified
7.2EPSS 0.005
CVE-2024-22389
BIG-IP iControl REST API Vulnerability
Published 2024-02-14 · Analyzed
7.2EPSS 0.005
CVE-2020-5880
Om BIG-IP 15.0.0-15.0.1.3 and 14.1.0-14.1.2.3, the restjavad process may expose a way for attackers to upload arbitrary files on the BIG-IP system, bypassing the authorization system. Resulting error messages may also reveal internal paths of the server.
Published 2020-04-30 · Modified
7.1EPSS 0.013
CVE-2019-6608
On BIG-IP 11.5.1-11.6.3, 12.1.0-12.1.3, 13.0.0-13.1.1.1, and 14.0.0-14.0.0.2, under certain conditions, the snmpd daemon may leak memory on a multi-blade BIG-IP vCMP guest when processing authorized SNMP requests.
Published 2019-03-28 · Modified
7.1EPSS 0.010
CVE-2026-42919
F5 BIG-IP Appliance Mode Vulnerability
Published 2026-05-13 · Analyzed
7.1EPSS 0.004
CVE-2026-40699
BIG-IP Configuration utility vulnerability
Published 2026-05-13 · Analyzed
7.1EPSS 0.004
CVE-2026-41219
BIG-IP QKView vulnerability
Published 2026-05-13 · Analyzed
7.1EPSS 0.004
CVE-2026-35062
iControl SOAP vulnerability
Published 2026-05-13 · Analyzed
7.1EPSS 0.003
CVE-2026-40462
iControl REST and tmsh vulnerability
Published 2026-05-13 · Analyzed
7.1EPSS 0.003
CVE-2020-5912
In BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the restjavad process's dump command does not follow current best coding practices and may overwrite arbitrary files.
Published 2020-08-26 · Modified
7.1EPSS 0.003
CVE-2026-42937
iControl REST and tmsh vulnerability
Published 2026-05-13 · Analyzed
7.1EPSS 0.003
CVE-2026-41959
iControl and tmsh REST vulnerability
Published 2026-05-13 · Analyzed
7.1EPSS 0.003
CVE-2026-42781
BIG-IP FastL4 virtual server vulnerability
Published 2026-05-13 · Analyzed
7.1EPSS 0.003
CVE-2014-0196
The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privileges by triggering a race condition involving read and write operations with long strings.
Published 2014-05-07 · Analyzed
6.9KEV1 PoCEPSS 0.225
CVE-2025-54755
BIG-IP Configuration utility vulnerability
Published 2025-10-15 · Analyzed
6.9EPSS 0.012
CVE-2026-24464
Appliance mode iControl REST vulnerability
Published 2026-05-13 · Analyzed
6.9EPSS 0.009
CVE-2025-54500
HTTP/2 Vulnerability
Published 2025-08-13 · Analyzed
6.9EPSS 0.005
CVE-2025-59268
BIG-IP Configuration utility vulnerability
Published 2025-10-15 · Analyzed
6.9EPSS 0.004
CVE-2026-41954
iControl REST and tmsh vulnerability
Published 2026-05-13 · Analyzed
6.9EPSS 0.004
CVE-2026-42063
iControl SOAP vulnerability
Published 2026-05-13 · Analyzed
6.9EPSS 0.004
CVE-2026-40435
BIG-IP httpd access control vulnerability
Published 2026-05-13 · Analyzed
6.9EPSS 0.003
CVE-2019-6604
On BIG-IP 11.5.1-11.5.8, 11.6.1-11.6.3, 12.1.0-12.1.3.6, 13.0.0-13.1.1.1, and 14.0.0-14.0.0.2, under certain conditions, hardware systems with a High-Speed Bridge and using non-default Layer 2 forwarding configurations may experience a lockup of the High-Speed Bridge.
Published 2019-03-28 · Modified
6.8EPSS 0.010
CVE-2022-27878
On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP, and F5 BIG-IP Guided Configuration (GC) all versions prior to 9.0, a stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to execute JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Published 2022-05-05 · Modified
6.8EPSS 0.009
CVE-2020-5916
In BIG-IP versions 15.1.0-15.1.0.4 and 15.0.0-15.0.1.3 the Certificate Administrator user role and higher privileged roles can perform arbitrary file reads outside of the web root directory.
Published 2020-08-26 · Modified
6.8EPSS 0.005
CVE-2022-33962
BIG-IP iRule vulnerability CVE-2022-33962
Published 2022-08-04 · Modified
6.7EPSS 0.002
CVE-2024-21782
BIG-IP and BIG-IQ secure copy vulnerability
Published 2024-02-14 · Analyzed
6.7EPSS 0.002
CVE-2026-42408
BIG-IP DNS tmsh vulnerability
Published 2026-05-13 · Analyzed
6.7EPSS 0.001
CVE-2019-6617
On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, a user with the Resource Administrator role is able to overwrite sensitive low-level files (such as /etc/passwd) using SFTP to modify user permissions, without Advanced Shell access. This is contrary to our definition for the Resource Administrator (RA) role restrictions.
Published 2019-05-03 · Modified
6.5EPSS 0.022
CVE-2019-6641
On BIG-IP 12.1.0-12.1.4.1, undisclosed requests can cause iControl REST processes to crash. The attack can only come from an authenticated user; all roles are capable of performing the attack. Unauthenticated users cannot perform this attack.
Published 2019-07-03 · Modified
6.5EPSS 0.020
CVE-2021-23043
On BIG-IP, on all versions of 16.1.x, 16.0.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x, a directory traversal vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to access arbitrary files. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published 2021-09-14 · Modified
6.5EPSS 0.020
CVE-2019-6638
On BIG-IP 14.1.0-14.1.0.5 and 14.0.0-14.0.0.4, Malformed http requests made to an undisclosed iControl REST endpoint can lead to infinite loop of the restjavad process.
Published 2019-07-03 · Modified
6.5EPSS 0.020
CVE-2019-6634
On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, and 12.1.0-12.1.4, a high volume of malformed analytics report requests leads to instability in restjavad process. This causes issues with both iControl REST and some portions of TMUI. The attack requires an authenticated user with any role.
Published 2019-07-03 · Modified
6.5EPSS 0.014
CVE-2019-6614
On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, and 12.1.0-12.1.4, internal methods used to prevent arbitrary file overwrites in Appliance Mode were not fully effective. An authenticated attacker with a high privilege level may be able to bypass protections implemented in appliance mode to overwrite arbitrary system files.
Published 2019-05-03 · Modified
6.5EPSS 0.014
CVE-2018-15322
On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, 11.6.0-11.6.3.2, or 11.2.1-11.5.6, BIG-IQ Centralized Management 6.0.0-6.0.1, 5.0.0-5.4.0 or 4.6.0, BIG-IQ Cloud and Orchestration 1.0.0, iWorkflow 2.0.1-2.3.0, or Enterprise Manager 3.1.1 a BIG-IP user granted with tmsh access may cause the BIG-IP system to experience denial-of-service (DoS) when the BIG-IP user uses the tmsh utility to run the edit cli preference command and proceeds to save the changes to another filename repeatedly. This action utilises storage space on the /var partition and when performed repeatedly causes the /var partition to be full.
Published 2018-10-31 · Modified
6.5EPSS 0.011
CVE-2017-6158
In F5 BIG-IP 12.0.0-12.1.2, 11.6.0-11.6.1, 11.5.1-11.5.5, or 11.2.1 there is a vulnerability in TMM related to handling of invalid IP addresses.
Published 2018-04-13 · Modified
6.5EPSS 0.011
CVE-2022-23023
On BIG-IP version 16.1.x before 16.1.2.1, 15.1.x before 15.1.5, 14.1.x before 14.1.4.5, and all versions of 13.1.x and 12.1.x, and BIG-IQ all versions of 8.x and 7.x, undisclosed requests by an authenticated iControl REST user can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published 2022-01-25 · Modified
6.5EPSS 0.009
← Prev9 / 13Next →