VendorsF5big-ip_ddos_hybrid_defenderall versions
Vulnerabilities

F5 Big-ip Ddos Hybrid Defender

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

166CVEs
CVE-2025-36504
BIG-IP HTTP/2 vulnerability
Published 2025-05-07 · Analyzed
8.7EPSS 0.004
CVE-2025-41399
SCTP Vulnerability
Published 2025-05-07 · Analyzed
8.7EPSS 0.004
CVE-2025-41414
BIG-IP HTTP/2 vulnerability
Published 2025-05-07 · Analyzed
8.7EPSS 0.004
CVE-2025-20045
BIG-IP SIP MRF Vulnerability
Published 2025-02-05 · Analyzed
8.7EPSS 0.004
CVE-2026-32673
BIG-IP scripted monitor vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.004
CVE-2026-40698
iControl REST and TMSH vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.004
CVE-2026-42924
BIG-IP iControl SOAP vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.004
CVE-2026-40631
BIG-IP iControl SOAP vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.004
CVE-2026-41953
BIG-IP Privilege Escalation vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.004
CVE-2025-59481
BIG-IP iControl REST and tmsh vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.004
CVE-2025-61958
BIG-IP TMSH vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.004
CVE-2025-58071
BIG-IP IPSec vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.004
CVE-2025-53856
TMM vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.003
CVE-2025-53474
BIG-IP iRules vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.003
CVE-2025-61990
TMM vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.003
CVE-2025-59781
BIG-IP DNS cache vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.003
CVE-2025-52585
BIG-IP Client SSL profile vulnerability
Published 2025-08-13 · Analyzed
8.7EPSS 0.003
CVE-2026-32643
BIG-IP and BIG-IQ privilege escalation vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.003
CVE-2026-42406
BIG-IP and BIG-IQ privilege escalation vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.003
CVE-2025-61951
BIG-IP DTLS 1.2 Vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.002
CVE-2024-45844
BIG-IP monitors vulnerability
Published 2024-10-16 · Analyzed
8.6EPSS 0.106
CVE-2026-39459
iControl REST and tmsh vulnerability
Published 2026-05-13 · Analyzed
8.6EPSS 0.005
CVE-2023-22374
iControl SOAP vulnerability
Published 2023-02-01 · Modified
8.5EPSS 0.726
CVE-2025-59483
BIG-IP Configuration utility and tmsh vulnerability
Published 2025-10-15 · Analyzed
8.5EPSS 0.004
CVE-2025-59269
BIG-IP Configuration utility XSS vulnerability
Published 2025-10-15 · Analyzed
8.4EPSS 0.003
CVE-2021-22978
On BIG-IP version 16.0.x before 16.0.1, 15.1.x before 15.1.1, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.5, and all 12.1.x and 11.6.x versions, undisclosed endpoints in iControl REST allow for a reflected XSS attack, which could lead to a complete compromise of BIG-IP if the victim user is granted the admin role. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Published 2021-02-12 · Modified
8.3EPSS 0.008
CVE-2026-41217
BIG-IP tmsh vulnerability
Published 2026-05-13 · Analyzed
8.3EPSS 0.002
CVE-2024-41164
BIG-IP MPTCP vulnerability
Published 2024-08-14 · Analyzed
8.2EPSS 0.004
CVE-2025-58096
BIG-IP TMM vulnerability
Published 2025-10-15 · Analyzed
8.2EPSS 0.003
CVE-2021-23012
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, and 13.1.x before 13.1.4, lack of input validation for items used in the system support functionality may allow users granted either "Resource Administrator" or "Administrator" roles to execute arbitrary bash commands on BIG-IP. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published 2021-05-10 · Modified
8.2EPSS 0.003
CVE-2025-58153
BIG-IP HSB vulnerability
Published 2025-10-15 · Analyzed
8.2EPSS 0.002
CVE-2023-40537
Multi-blade VIPRION Configuration utility session cookie vulnerability
Published 2023-10-10 · Modified
8.1EPSS 0.005
CVE-2024-31156
BIG-IP Configuration utility XSS vulnerability
Published 2024-05-08 · Analyzed
8.0EPSS 0.006
CVE-2025-24320
BIG-IP Configuration utility vulnerability
Published 2025-02-05 · Analyzed
8.0EPSS 0.004
CVE-2023-43611
BIG-IP Edge Client for macOS vulnerability
Published 2023-10-10 · Modified
7.8EPSS 0.001
CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Published 2023-10-10 · Analyzed
7.5KEV1 PoCEPSS 1.000
CVE-2002-20001
The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network bandwidth. The attack may be more disruptive in cases where a client can require a server to select its largest supported key size. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE.
Published 2021-11-11 · Analyzed
7.5EPSS 0.246
CVE-2021-22977
On BIG-IP version 16.0.0-16.0.1 and 14.1.2.4-14.1.3, cooperation between malicious HTTP client code and a malicious server may cause TMM to restart and generate a core file. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Published 2021-02-12 · Modified
7.5EPSS 0.011
CVE-2020-5949
On BIG-IP versions 14.0.0-14.0.1 and 13.1.0-13.1.3.4, certain traffic pattern sent to a virtual server configured with an FTP profile can cause the FTP channel to break.
Published 2020-12-11 · Modified
7.5EPSS 0.010
CVE-2020-5939
In versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.3, 15.0.0-15.0.1.3, 14.1.0-14.1.2.6, and 13.1.0-13.1.3.4, BIG-IP Virtual Edition (VE) systems on VMware, with an Intel-based 85299 Network Interface Controller (NIC) card and Single Root I/O Virtualization (SR-IOV) enabled on vSphere, may fail and leave the Traffic Management Microkernel (TMM) in a state where it cannot transmit traffic.
Published 2020-11-05 · Modified
7.5EPSS 0.010
← Prev2 / 5Next →