VendorsF5big-ip_application_acceleration_managerany version
Vulnerabilities

F5 Big-ip Application Acceleration Manager any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

431CVEs
CVE-2025-58071
BIG-IP IPSec vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.004
CVE-2025-59781
BIG-IP DNS cache vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.003
CVE-2025-61990
TMM vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.003
CVE-2025-53856
TMM vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.003
CVE-2025-53474
BIG-IP iRules vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.003
CVE-2025-52585
BIG-IP Client SSL profile vulnerability
Published 2025-08-13 · Analyzed
8.7EPSS 0.003
CVE-2026-32643
BIG-IP and BIG-IQ privilege escalation vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.003
CVE-2026-42406
BIG-IP and BIG-IQ privilege escalation vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.003
CVE-2025-61951
BIG-IP DTLS 1.2 Vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.002
CVE-2024-45844
BIG-IP monitors vulnerability
Published 2024-10-16 · Analyzed
8.6EPSS 0.106
CVE-2026-39459
iControl REST and tmsh vulnerability
Published 2026-05-13 · Analyzed
8.6EPSS 0.005
CVE-2023-22374
iControl SOAP vulnerability
Published 2023-02-01 · Modified
8.5EPSS 0.726
CVE-2020-5945
In BIG-IP versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.2.7, undisclosed TMUI page contains a stored cross site scripting vulnerability (XSS). The issue allows a minor privilege escalation for resource admin to escalate to full admin.
Published 2020-11-05 · Modified
8.5EPSS 0.013
CVE-2017-6167
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM and WebSafe software version 13.0.0 and 12.1.0 - 12.1.2, race conditions in iControl REST may lead to commands being executed with different privilege levels than expected.
Published 2017-12-21 · Modified
8.5EPSS 0.011
CVE-2025-59483
BIG-IP Configuration utility and tmsh vulnerability
Published 2025-10-15 · Analyzed
8.5EPSS 0.004
CVE-2025-59269
BIG-IP Configuration utility XSS vulnerability
Published 2025-10-15 · Analyzed
8.4EPSS 0.003
CVE-2021-22978
On BIG-IP version 16.0.x before 16.0.1, 15.1.x before 15.1.1, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.5, and all 12.1.x and 11.6.x versions, undisclosed endpoints in iControl REST allow for a reflected XSS attack, which could lead to a complete compromise of BIG-IP if the victim user is granted the admin role. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Published 2021-02-12 · Modified
8.3EPSS 0.008
CVE-2026-41217
BIG-IP tmsh vulnerability
Published 2026-05-13 · Analyzed
8.3EPSS 0.002
CVE-2024-41164
BIG-IP MPTCP vulnerability
Published 2024-08-14 · Analyzed
8.2EPSS 0.004
CVE-2025-58096
BIG-IP TMM vulnerability
Published 2025-10-15 · Analyzed
8.2EPSS 0.003
CVE-2021-23012
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, and 13.1.x before 13.1.4, lack of input validation for items used in the system support functionality may allow users granted either "Resource Administrator" or "Administrator" roles to execute arbitrary bash commands on BIG-IP. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published 2021-05-10 · Modified
8.2EPSS 0.003
CVE-2025-58153
BIG-IP HSB vulnerability
Published 2025-10-15 · Analyzed
8.2EPSS 0.002
CVE-2019-6974
In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles reference counting because of a race condition, leading to a use-after-free.
Published 2019-02-15 · Modified
8.11 PoCEPSS 0.165
CVE-2017-6157
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and Websafe software version 12.0.0 to 12.1.1, 11.6.0 to 11.6.1, 11.5.0 - 11.5.4, virtual servers with a configuration using the HTTP Explicit Proxy functionality and/or SOCKS profile are vulnerable to an unauthenticated, remote attack that allows modification of BIG-IP system configuration, extraction of sensitive system files, and/or possible remote command execution on the BIG-IP system.
Published 2017-10-27 · Modified
8.1EPSS 0.040
CVE-2017-6164
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, WebAccelerator and WebSafe software version 13.0.0, 12.0.0 - 12.1.2, 11.6.0 - 11.6.1 and 11.5.0 - 11.5.4, in some circumstances, Traffic Management Microkernel (TMM) does not properly handle certain malformed TLS1.2 records, which allows remote attackers to cause a denial-of-service (DoS) or possible remote command execution on the BIG-IP system.
Published 2017-12-21 · Modified
8.1EPSS 0.039
CVE-2018-5542
F5 BIG-IP 13.0.0-13.0.1, 12.1.0-12.1.3.6, or 11.2.1-11.6.3.2 HTTPS health monitors do not validate the identity of the monitored server.
Published 2018-07-25 · Modified
8.1EPSS 0.012
CVE-2020-5906
In versions 13.1.0-13.1.3.3, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, the BIG-IP system does not properly enforce the access controls for the scp.blacklist files. This allows Admin and Resource Admin users with Secure Copy (SCP) protocol access to read and overwrite blacklisted files via SCP.
Published 2020-07-01 · Modified
8.1EPSS 0.012
CVE-2020-5860
On BIG-IP 15.0.0-15.1.0.2, 14.1.0-14.1.2.3, 13.1.0-13.1.3.2, 12.1.0-12.1.5.1, and 11.5.2-11.6.5.1 and BIG-IQ 7.0.0, 6.0.0-6.1.0, and 5.2.0-5.4.0, in a High Availability (HA) network failover in Device Service Cluster (DSC), the failover service does not require a strong form of authentication and HA network failover traffic is not encrypted by Transport Layer Security (TLS).
Published 2020-03-27 · Modified
8.1EPSS 0.008
CVE-2020-5888
On versions 15.1.0-15.1.0.1, 15.0.0-15.0.1.2, and 14.1.0-14.1.2.3, BIG-IP Virtual Edition (VE) may expose a mechanism for adjacent network (layer 2) attackers to access local daemons and bypass port lockdown settings.
Published 2020-04-30 · Modified
8.1EPSS 0.006
CVE-2020-5876
On BIG-IP 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, a race condition exists where mcpd and other processes may make unencrypted connection attempts to a new configuration sync peer. The race condition can occur when changing the ConfigSync IP address of a peer, adding a new peer, or when the Traffic Management Microkernel (TMM) first starts up.
Published 2020-04-30 · Modified
8.1EPSS 0.006
CVE-2023-40537
Multi-blade VIPRION Configuration utility session cookie vulnerability
Published 2023-10-10 · Modified
8.1EPSS 0.005
CVE-2024-31156
BIG-IP Configuration utility XSS vulnerability
Published 2024-05-08 · Analyzed
8.0EPSS 0.006
CVE-2025-24320
BIG-IP Configuration utility vulnerability
Published 2025-02-05 · Analyzed
8.0EPSS 0.004
CVE-2019-11477
Integer overflow in TCP_SKB_CB(skb)->tcp_gso_segs
Published 2019-06-18 · Modified
7.8EPSS 0.987
CVE-2018-5390
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service
Published 2018-08-06 · Modified
7.8EPSS 0.737
CVE-2018-5391
The Linux kernel, versions 3.9+, IP implementation is vulnerable to denial of service conditions with low rates of specially modified packets
Published 2018-09-06 · Modified
7.8EPSS 0.324
CVE-2018-14634
An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on the system. Kernel versions 2.6.x, 3.10.x and 4.14.x are believed to be vulnerable.
Published 2018-09-25 · Analyzed
7.8KEV1 PoCEPSS 0.147
CVE-2015-4047
racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a series of crafted UDP requests.
Published 2015-05-29 · Modified
7.8EPSS 0.098
CVE-2014-0101
The sctp_sf_do_5_1D_ce function in net/sctp/sm_statefuns.c in the Linux kernel through 3.13.6 does not validate certain auth_enable and auth_capable fields before making an sctp_sf_authenticate call, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via an SCTP handshake with a modified INIT chunk and a crafted AUTH chunk before a COOKIE_ECHO chunk.
Published 2014-03-11 · Modified
7.8EPSS 0.070
CVE-2018-5512
On F5 BIG-IP 13.1.0-13.1.0.5, when Large Receive Offload (LRO) and SYN cookies are enabled (default settings), undisclosed traffic patterns may cause TMM to restart.
Published 2018-05-02 · Modified
7.8EPSS 0.030
← Prev3 / 11Next →