VendorsF5big-ip_application_acceleration_managerall versions
Vulnerabilities

F5 Big-ip Application Acceleration Manager

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

523CVEs
CVE-2021-23013
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, the Traffic Management Microkernel (TMM) may stop responding when processing Stream Control Transmission Protocol (SCTP) traffic under certain conditions. This vulnerability affects TMM by way of a virtual server configured with an SCTP profile. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published 2021-05-10 · Modified
7.5EPSS 0.009
CVE-2021-22974
On BIG-IP version 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, and 13.1.x before 13.1.3.6 and all versions of BIG-IQ 7.x and 6.x, an authenticated attacker with access to iControl REST over the control plane may be able to take advantage of a race condition to execute commands with an elevated privilege level. This vulnerability is due to an incomplete fix for CVE-2017-6167. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Published 2021-02-12 · Modified
7.5EPSS 0.008
CVE-2022-26370
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5, and 14.1.x versions prior to 14.1.4.6, when a Session Initiation Protocol (SIP) message routing framework (MRF) application layer gateway (ALG) profile is configured on a Message Routing virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Published 2022-05-05 · Modified
7.5EPSS 0.008
CVE-2022-29473
On F5 BIG-IP 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, when an IPSec ALG profile is configured on a virtual server, undisclosed responses can cause Traffic Management Microkernel(TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Published 2022-05-05 · Modified
7.5EPSS 0.008
CVE-2022-26517
On F5 BIG-IP 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, when the BIG-IP CGNAT Large Scale NAT (LSN) pool is configured on a virtual server and packet filtering is enabled, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Published 2022-05-05 · Modified
7.5EPSS 0.008
CVE-2022-28706
On F5 BIG-IP 16.1.x versions prior to 16.1.2 and 15.1.x versions prior to 15.1.5.1, when the DNS resolver configuration is used, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Published 2022-05-05 · Modified
7.5EPSS 0.008
CVE-2022-34651
BIG-IP TLS 1.3 iRule vulnerability CVE-2022-34651
Published 2022-08-04 · Modified
7.5EPSS 0.007
CVE-2022-34655
TMM vulnerability CVE-2022-34655
Published 2022-08-04 · Modified
7.5EPSS 0.007
CVE-2022-35236
HTTP2 profile vulnerability CVE-2022-35236
Published 2022-08-04 · Modified
7.5EPSS 0.007
CVE-2022-35240
BIG-IP Message Routing MQTT vulnerability CVE-2022-35240
Published 2022-08-04 · Modified
7.5EPSS 0.007
CVE-2022-34844
BIG-IP and BIG-IQ AWS vulnerability CVE-2022-34844
Published 2022-08-04 · Modified
7.5EPSS 0.007
CVE-2022-36795
BIG-IP software SYN cookies vulnerability CVE-2022-36795
Published 2022-10-19 · Modified
7.5EPSS 0.007
CVE-2022-41624
BIG-IP iRules vulnerability CVE-2022-41624
Published 2022-10-19 · Modified
7.5EPSS 0.007
CVE-2022-41832
BIG-IP SIP vulnerability CVE-2022-41832
Published 2022-10-19 · Modified
7.5EPSS 0.007
CVE-2022-41833
BIG-IP iRule vulnerability CVE-2022-41833
Published 2022-10-19 · Modified
7.5EPSS 0.007
CVE-2023-22323
BIG-IP SSL OCSP Authentication profile vulnerability
Published 2023-02-01 · Modified
7.5EPSS 0.007
CVE-2022-23015
On BIG-IP versions 16.x before 16.1.0, 15.1.x before 15.1.4.1, and 14.1.2.6-14.1.4.4, when a Client SSL profile is configured on a virtual server with Client Certificate Authentication set to request/require and Session Ticket enabled and configured, processing SSL traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published 2022-01-25 · Modified
7.5EPSS 0.006
CVE-2023-22340
BIG-IP SIP profile vulnerability
Published 2023-02-01 · Modified
7.5EPSS 0.006
CVE-2023-22422
HTTP profile vulnerability
Published 2023-02-01 · Modified
7.5EPSS 0.006
CVE-2023-22664
BIG-IP HTTP/2 profile vulnerability
Published 2023-02-01 · Modified
7.5EPSS 0.006
CVE-2023-22842
BIG-IP SIP profile vulnerability
Published 2023-02-01 · Modified
7.5EPSS 0.006
CVE-2023-23555
BIG-IP Virtual Edition vulnerability
Published 2023-02-01 · Modified
7.5EPSS 0.006
CVE-2023-29163
BIG-IP UDP Profile vulnerability
Published 2023-05-03 · Modified
7.5EPSS 0.006
CVE-2024-33608
BIG-IP IPsec vulnerability
Published 2024-05-08 · Analyzed
7.5EPSS 0.006
CVE-2023-40534
BIG-IP HTTP/2 vulnerability
Published 2023-10-10 · Modified
7.5EPSS 0.005
CVE-2023-40542
BIG-IP TCP Profile vulnerability
Published 2023-10-10 · Analyzed
7.5EPSS 0.005
CVE-2024-25560
TMM Vulnerability
Published 2024-05-08 · Analyzed
7.5EPSS 0.005
CVE-2024-24775
BIG-IP TMM vulnerability
Published 2024-02-14 · Analyzed
7.5EPSS 0.005
CVE-2024-23314
BIG-IP HTTP/2 vulnerability
Published 2024-02-14 · Analyzed
7.5EPSS 0.005
CVE-2023-41085
BIG-IP IPSEC vulnerability
Published 2023-10-10 · Modified
7.5EPSS 0.005
CVE-2022-32455
TMM vulnerability CVE-2022-32455
Published 2022-08-04 · Modified
7.5EPSS 0.005
CVE-2022-35272
BIG-IP HTTP MRF vulnerability CVE-2022-35272
Published 2022-08-04 · Modified
7.5EPSS 0.005
CVE-2023-38138
BIG-IP Configuration utility vulnerability
Published 2023-08-02 · Modified
7.5EPSS 0.004
CVE-2023-27378
BIG-IP TMUI XSS vulnerability
Published 2023-05-03 · Modified
7.5EPSS 0.004
CVE-2024-23979
BIG-IP SSL Client Certificate LDAP and CRLDP Authentication profiles vulnerability
Published 2024-02-14 · Analyzed
7.5EPSS 0.003
CVE-2017-6168
On BIG-IP versions 11.6.0-11.6.2 (fixed in 11.6.2 HF1), 12.0.0-12.1.2 HF1 (fixed in 12.1.2 HF2), or 13.0.0-13.0.0 HF2 (fixed in 13.0.0 HF3) a virtual server configured with a Client SSL profile may be vulnerable to an Adaptive Chosen Ciphertext attack (AKA Bleichenbacher attack) against RSA, which when exploited, may result in plaintext recovery of encrypted messages and/or a Man-in-the-middle (MiTM) attack, despite the attacker not having gained access to the server's private key itself, aka a ROBOT attack.
Published 2017-11-17 · Modified
7.4EPSS 0.196
CVE-2016-2084
F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.x, 11.4.x before 11.4.1 build 685-HF10, 11.5.1 before build 10.104.180, 11.5.2 before 11.5.4 build 0.1.256, 11.6.0 before build 6.204.442, and 12.0.0 before build 1.14.628; BIG-IP AAM 11.4.x before 11.4.1 build 685-HF10, 11.5.1 before build 10.104.180, 11.5.2 before 11.5.4 build 0.1.256, 11.6.0 before build 6.204.442, and 12.0.0 before build 1.14.628; BIG-IP DNS 12.0.0 before build 1.14.628; BIG-IP Edge Gateway, WebAccelerator, and WOM 11.3.0; BIG-IP GTM 11.3.x, 11.4.x before 11.4.1 build 685-HF10, 11.5.1 before build 10.104.180, 11.5.2 before 11.5.4 build 0.1.256, and 11.6.0 before build 6.204.442; BIG-IP PSM 11.3.x and 11.4.x before 11.4.1 build 685-HF10; BIG-IQ Cloud, Device, and Security 4.2.0 through 4.5.0; and BIG-IQ ADC 4.5.0 do not properly regenerate certificates and keys when deploying cloud images in Amazon Web Services (AWS), Azure or Verizon cloud services environments, which allows attackers to obtain sensitive information or cause a denial of service (disruption) by leveraging a target instance configuration.
Published 2016-04-13 · Modified
7.4EPSS 0.008
CVE-2018-5531
Through undisclosed methods, on F5 BIG-IP 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, 11.6.0-11.6.3.1, or 11.2.1-11.5.6, adjacent network attackers can cause a denial of service for VCMP guest and host systems. Attack must be sourced from adjacent network (layer 2).
Published 2018-07-25 · Modified
7.4EPSS 0.005
CVE-2020-5913
In versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2, the BIG-IP Client or Server SSL profile ignores revoked certificates, even when a valid CRL is present. This impacts SSL/TLS connections and may result in a man-in-the-middle attack on the connections.
Published 2020-08-26 · Modified
7.4EPSS 0.005
CVE-2015-7393
dcoep in BIG-IP LTM, Analytics, APM, ASM, and Link Controller 11.2.0 through 11.6.0 and 12.0.0 before 12.0.0 HF1, BIG-IP AAM 11.4.0 through 11.6.0 and 12.0.0 before 12.0.0 HF1, BIG-IP AFM and PEM 11.3.0 through 11.6.0 and 12.0.0 before 12.0.0 HF1, BIG-IP DNS 12.0.0 before 12.0.0 HF1, BIG-IP Edge Gateway, WebAccelerator, and WOM 11.2.0 through 11.3.0, BIG-IP GTM 11.2.0 through 11.6.0, BIG-IP PSM 11.2.0 through 11.4.1, Enterprise Manager 3.0.0 through 3.1.1, BIG-IQ Cloud 4.0.0 through 4.5.0, BIG-IQ Device 4.2.0 through 4.5.0, BIG-IQ Security 4.0.0 through 4.5.0, BIG-IQ ADC 4.5.0, BIG-IQ Centralized Management 4.6.0, and BIG-IQ Cloud and Orchestration 1.0.0 allows local users with advanced shell (bash) access to gain privileges via unspecified vectors.
Published 2016-01-12 · Modified
7.4EPSS 0.003
← Prev8 / 14Next →