VendorsF5big-ip_ddos_hybrid_defenderall versions
Vulnerabilities

F5 Big-ip Ddos Hybrid Defender

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

166CVEs
CVE-2020-5902
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulnerability in undisclosed pages.
Published 2020-07-01 · Analyzed
10.0KEV3 PoCEPSS 1.000
CVE-2021-22986
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an unauthenticated remote command execution vulnerability. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Published 2021-03-31 · Analyzed
10.0KEV1 PoCEPSS 0.999
CVE-2021-22987
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3 when running in Appliance mode, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has an authenticated remote command execution vulnerability in undisclosed pages. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Published 2021-03-31 · Modified
9.9EPSS 0.137
CVE-2023-41373
BIG-IP Configuration Utility vulnerability
Published 2023-10-10 · Modified
9.9EPSS 0.024
CVE-2023-46747
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
Published 2023-10-26 · Analyzed
9.8KEVEPSS 0.965
CVE-2021-22992
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, a malicious HTTP response to an Advanced WAF/BIG-IP ASM virtual server with Login Page configured in its policy may trigger a buffer overflow, resulting in a DoS attack. In certain situations, it may allow remote code execution (RCE), leading to complete system compromise. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Published 2021-03-31 · Modified
9.8EPSS 0.727
CVE-2021-22991
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, undisclosed requests to a virtual server may be incorrectly handled by the Traffic Management Microkernel (TMM) URI normalization, which may trigger a buffer overflow, resulting in a DoS attack. In certain situations, it may theoretically allow bypass of URL based access control or remote code execution (RCE). Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Published 2021-03-31 · Analyzed
9.8KEVEPSS 0.611
CVE-2020-5922
In BIG-IP versions 15.0.0-15.1.0.4, 14.1.0-14.1.2.6, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2, iControl REST does not implement Cross Site Request Forgery protections for users which make use of Basic Authentication in a web browser.
Published 2020-08-26 · Modified
9.3EPSS 0.006
CVE-2021-22989
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, when running in Appliance mode with Advanced WAF or BIG-IP ASM provisioned, the TMUI, also referred to as the Configuration utility, has an authenticated remote command execution vulnerability in undisclosed pages. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Published 2021-03-31 · Modified
9.1EPSS 0.088
CVE-2026-41225
iControl REST vulnerability
Published 2026-05-13 · Analyzed
9.1EPSS 0.003
CVE-2021-22988
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, TMUI, also referred to as the Configuration utility, has an authenticated remote command execution vulnerability in undisclosed pages. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Published 2021-03-31 · Modified
9.0EPSS 0.104
CVE-2021-22990
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, on systems with Advanced WAF or BIG-IP ASM provisioned, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has an authenticated remote command execution vulnerability in undisclosed pages. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Published 2021-03-31 · Modified
9.0EPSS 0.088
CVE-2025-21087
TMM Vulnerability
Published 2025-02-05 · Analyzed
8.9EPSS 0.004
CVE-2025-20058
BIG-IP message routing vulnerability
Published 2025-02-05 · Analyzed
8.9EPSS 0.004
CVE-2025-20029
BIG-IP iControl REST and tmsh vulnerability
Published 2025-02-05 · Analyzed
8.8EPSS 0.072
CVE-2023-46748
BIG-IP Configuration utility authenticated SQL injection vulnerability
Published 2023-10-26 · Analyzed
8.8KEVEPSS 0.045
CVE-2021-23025
On version 15.1.x before 15.1.0.5, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.5, and all versions of 12.1.x and 11.6.x, an authenticated remote command execution vulnerability exists in the BIG-IP Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published 2021-09-14 · Modified
8.8EPSS 0.023
CVE-2026-41957
BIG-IP and BIG-IQ Configuration utility vulnerability
Published 2026-05-13 · Analyzed
8.8EPSS 0.005
CVE-2021-23026
BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x and 11.6.x and all versions of BIG-IQ 8.x, 7.x, and 6.x are vulnerable to cross-site request forgery (CSRF) attacks through iControl SOAP. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published 2021-09-14 · Modified
8.8EPSS 0.005
CVE-2025-31644
Appliance mode BIG-IP iControl REST and tmsh vulnerability
Published 2025-05-07 · Analyzed
8.7EPSS 0.265
CVE-2026-34176
Knowledge Appliance mode iControl REST vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.007
CVE-2024-41727
BIG-IP TMM vulnerability
Published 2024-08-14 · Analyzed
8.7EPSS 0.005
CVE-2024-39778
BIG-IP HSB vulnerability
Published 2024-08-14 · Analyzed
8.7EPSS 0.005
CVE-2026-42930
Appliance mode iControl REST vulnerability
Published 2026-05-13 · Undergoing Analysis
8.7EPSS 0.005
CVE-2025-21091
BIG-IP SNMP vulnerability
Published 2025-02-05 · Analyzed
8.7EPSS 0.005
CVE-2025-53868
BIG-IP SCP and SFTP vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.004
CVE-2025-48008
BIG-IP MPTCP vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.004
CVE-2023-43746
BIG-IP Appliance mode external monitor vulnerability
Published 2023-10-10 · Modified
8.7EPSS 0.004
CVE-2025-46706
BIG-IP iRules vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.004
CVE-2025-36504
BIG-IP HTTP/2 vulnerability
Published 2025-05-07 · Analyzed
8.7EPSS 0.004
CVE-2025-41433
BIG-IP SIP ALG profile vulnerability
Published 2025-05-07 · Analyzed
8.7EPSS 0.004
CVE-2025-41399
SCTP Vulnerability
Published 2025-05-07 · Analyzed
8.7EPSS 0.004
CVE-2025-41414
BIG-IP HTTP/2 vulnerability
Published 2025-05-07 · Analyzed
8.7EPSS 0.004
CVE-2025-20045
BIG-IP SIP MRF Vulnerability
Published 2025-02-05 · Analyzed
8.7EPSS 0.004
CVE-2025-59481
BIG-IP iControl REST and tmsh vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.004
CVE-2025-61958
BIG-IP TMSH vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.004
CVE-2025-58071
BIG-IP IPSec vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.004
CVE-2025-53856
TMM vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.003
CVE-2025-61990
TMM vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.003
CVE-2025-59781
BIG-IP DNS cache vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.003
1 / 5Next →