VendorsF5big-ip_ddos_hybrid_defenderall versions
Vulnerabilities

F5 Big-ip Ddos Hybrid Defender

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

166CVEs
CVE-2025-54500
HTTP/2 Vulnerability
Published 2025-08-13 · Analyzed
6.9EPSS 0.005
CVE-2025-59268
BIG-IP Configuration utility vulnerability
Published 2025-10-15 · Analyzed
6.9EPSS 0.004
CVE-2026-41954
iControl REST and tmsh vulnerability
Published 2026-05-13 · Analyzed
6.9EPSS 0.004
CVE-2026-42063
iControl SOAP vulnerability
Published 2026-05-13 · Analyzed
6.9EPSS 0.004
CVE-2026-40435
BIG-IP httpd access control vulnerability
Published 2026-05-13 · Analyzed
6.9EPSS 0.003
CVE-2020-5916
In BIG-IP versions 15.1.0-15.1.0.4 and 15.0.0-15.0.1.3 the Certificate Administrator user role and higher privileged roles can perform arbitrary file reads outside of the web root directory.
Published 2020-08-26 · Modified
6.8EPSS 0.005
CVE-2026-42408
BIG-IP DNS tmsh vulnerability
Published 2026-05-13 · Analyzed
6.7EPSS 0.001
CVE-2022-23023
On BIG-IP version 16.1.x before 16.1.2.1, 15.1.x before 15.1.5, 14.1.x before 14.1.4.5, and all versions of 13.1.x and 12.1.x, and BIG-IQ all versions of 8.x and 7.x, undisclosed requests by an authenticated iControl REST user can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published 2022-01-25 · Modified
6.5EPSS 0.009
CVE-2020-5938
On BIG-IP 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, when negotiating IPSec tunnels with configured, authenticated peers, the peer may negotiate a different key length than the BIG-IP configuration would otherwise allow.
Published 2020-10-29 · Modified
6.5EPSS 0.005
CVE-2020-5943
In versions 14.1.0-14.1.0.1 and 14.1.2.5-14.1.2.7, when a BIG-IP object is created or listed through the REST interface, the protected fields are obfuscated in the REST response, not protected via a SecureVault cryptogram as TMSH does. One example of protected fields is the GTM monitor password.
Published 2020-11-05 · Modified
6.5EPSS 0.005
CVE-2024-32761
BIG-IP TMM tenants on VELOS and rSeries vulnerability
Published 2024-05-08 · Analyzed
6.5EPSS 0.005
CVE-2023-41964
BIG-IP and BIG-IQ Database Variable vulnerability
Published 2023-10-10 · Modified
6.5EPSS 0.002
CVE-2026-34019
BIG-IP BFD vulnerability
Published 2026-05-13 · Analyzed
6.3EPSS 0.004
CVE-2025-58424
BIG-IP TMM vulnerability
Published 2025-10-15 · Analyzed
6.3EPSS 0.002
CVE-2020-27719
On BIG-IP 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.3, a cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility.
Published 2020-12-24 · Modified
6.1EPSS 0.008
CVE-2021-22979
On BIG-IP version 16.0.x before 16.0.1, 15.1.x before 15.1.1, 14.1.x before 14.1.2.8, 13.1.x before 13.1.3.5, and all 12.1.x versions, a reflected Cross-Site Scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility when Fraud Protection Service is provisioned and allows an attacker to execute JavaScript in the context of the current logged-in user. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Published 2021-02-12 · Modified
6.1EPSS 0.006
CVE-2021-23027
On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, and 14.1.x before 14.1.4.3, a DOM based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to execute JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published 2021-09-14 · Modified
6.1EPSS 0.006
CVE-2021-22994
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, undisclosed endpoints in iControl REST allow for a reflected XSS attack, which could lead to a complete compromise of the BIG-IP system if the victim user is granted the admin role. This vulnerability is due to an incomplete fix for CVE-2020-5948. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Published 2021-03-31 · Modified
6.1EPSS 0.006
CVE-2023-22418
BIG-IP APM virtual server vulnerability
Published 2023-02-01 · Modified
6.1EPSS 0.003
CVE-2024-33604
BIG-IP Configuration utility XSS vulnerability
Published 2024-05-08 · Analyzed
6.1EPSS 0.003
CVE-2023-3470
BIG-IP FIPS HSM password vulnerability CVE-2023-3470
Published 2023-08-02 · Modified
6.1EPSS 0.002
CVE-2020-5929
In versions 13.0.0-13.0.0 HF2, 12.1.0-12.1.2 HF1, and 11.6.1-11.6.2, BIG-IP platforms with Cavium Nitrox SSL hardware acceleration cards, a Virtual Server configured with a Client SSL profile, and using Anonymous (ADH) or Ephemeral (DHE) Diffie-Hellman key exchange and Single DH use option not enabled in the options list may be vulnerable to crafted SSL/TLS Handshakes that may result with a PMS (Pre-Master Secret) that starts in a 0 byte and may lead to a recovery of plaintext messages as BIG-IP TLS/SSL ADH/DHE sends different error messages acting as an oracle. Similar error messages when PMS starts with 0 byte coupled with very precise timing measurement observation may also expose this vulnerability.
Published 2020-09-25 · Modified
5.9EPSS 0.011
CVE-2023-22302
BIG-IP HTTP profile vulnerability
Published 2023-02-01 · Modified
5.9EPSS 0.005
CVE-2024-28889
BIG-IP SSL vulnerability
Published 2024-05-08 · Analyzed
5.9EPSS 0.004
CVE-2021-22981
On all versions of BIG-IP 12.1.x and 11.6.x, the original TLS protocol includes a weakness in the master secret negotiation that is mitigated by the Extended Master Secret (EMS) extension defined in RFC 7627. TLS connections that do not use EMS are vulnerable to man-in-the-middle attacks during renegotiation. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Published 2021-02-12 · Modified
5.8EPSS 0.006
CVE-2023-43485
BIGIP and BIG-IQ TACACS+ audit log Vulnerability
Published 2023-10-10 · Modified
5.5EPSS 0.002
CVE-2023-38423
BIG-IP Configuration utility vulnerability
Published 2023-08-02 · Modified
5.4EPSS 0.003
CVE-2026-40703
BIG-IP Configuration utility CSRF vulnerability
Published 2026-05-13 · Analyzed
5.4EPSS 0.001
CVE-2021-23007
On BIG-IP versions 14.1.4 and 16.0.1.1, when the Traffic Management Microkernel (TMM) process handles certain undisclosed traffic, it may start dropping all fragmented IP traffic. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Published 2021-03-31 · Modified
5.3EPSS 0.016
CVE-2021-22998
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, SYN flood protection thresholds are not enforced in secure network address translation (SNAT) listeners. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Published 2021-03-31 · Modified
5.3EPSS 0.009
CVE-2022-23027
On BIG-IP versions 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, 13.1.x beginning in 13.1.3.6, 12.1.5.3-12.1.6, and 11.6.5.2, when a FastL4 profile and an HTTP, FIX, and/or hash persistence profile are configured on the same virtual server, undisclosed requests can cause the virtual server to stop processing new client connections. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published 2022-01-25 · Modified
5.3EPSS 0.009
CVE-2022-23030
On version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versions of 13.1.x, when the BIG-IP Virtual Edition (VE) uses the ixlv driver (which is used in SR-IOV mode and requires Intel X710/XL710/XXV710 family of network adapters on the Hypervisor) and TCP Segmentation Offload configuration is enabled, undisclosed requests may cause an increase in CPU resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published 2022-01-25 · Modified
5.3EPSS 0.009
CVE-2022-23029
On BIG-IP version 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x, 12.1.x, and 11.6.x, when a FastL4 profile is configured on a virtual server, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published 2022-01-25 · Modified
5.3EPSS 0.007
CVE-2023-24594
BIG-IP TMM SSL vulnerability
Published 2023-05-03 · Modified
5.3EPSS 0.006
CVE-2024-41723
BIG-IP iControl REST vulnerability
Published 2024-08-14 · Analyzed
5.3EPSS 0.003
CVE-2026-42058
BIG-IP iControl REST vulnerability
Published 2026-05-13 · Analyzed
5.3EPSS 0.003
CVE-2023-22326
iControl REST and tmsh vulnerability
Published 2023-02-01 · Modified
4.9EPSS 0.005
CVE-2024-27202
BIG-IP TMUI XSS vulnerability
Published 2024-05-08 · Analyzed
4.7EPSS 0.003
CVE-2023-45219
BIG-IP tmsh vulnerability
Published 2023-10-10 · Modified
4.4EPSS 0.002
CVE-2023-28406
BIG-IP Configuration utility vulnerability
Published 2023-05-03 · Modified
4.3EPSS 0.012
← Prev4 / 5Next →