VendorsF5big-ip_ddos_hybrid_defenderall versions
Vulnerabilities

F5 Big-ip Ddos Hybrid Defender

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

166CVEs
CVE-2020-5947
In versions 16.0.0-16.0.0.1 and 15.1.0-15.1.1, on specific BIG-IP platforms, attackers may be able to obtain TCP sequence numbers from the BIG-IP system that can be reused in future connections with the same source and destination port and IP numbers. Only these platforms are affected: BIG-IP 2000 series (C112), BIG-IP 4000 series (C113), BIG-IP i2000 series (C117), BIG-IP i4000 series (C115), BIG-IP Virtual Edition (VE).
Published 2020-11-19 · Modified
4.3EPSS 0.007
CVE-2021-23001
On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, the upload functionality in BIG-IP Advanced WAF and BIG-IP ASM allows an authenticated user to upload files to the BIG-IP system using a call to an undisclosed iControl REST endpoint. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Published 2021-03-31 · Modified
4.3EPSS 0.006
CVE-2023-38419
BIG-IP and BIG-IQ iControl SOAP vulnerability
Published 2023-08-02 · Modified
4.3EPSS 0.005
CVE-2026-20732
BIG-IP Configuration utility vulnerability
Published 2026-02-04 · Analyzed
4.3EPSS 0.002
CVE-2022-41983
BIG-IP TMM Vulnerability CVE-2022-41983
Published 2022-10-19 · Modified
3.7EPSS 0.003
CVE-2026-63020
BIG-IP Configuration utility vulnerability
Published 2026-09-02 · Analyzed
3.1EPSS 0.002
← Prev5 / 5