VendorsF5big-ip_edge_gatewayany version
Vulnerabilities

F5 Big-ip Edge Gateway any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

250CVEs
CVE-2014-6271
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
Published 2014-09-24 · Analyzed
10.0KEV21 PoCEPSS 1.000
CVE-2014-7169
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.
Published 2014-09-25 · Analyzed
10.0KEV15 PoCEPSS 0.999
CVE-2019-6609
Platform dependent weakness. This issue only impacts iSeries platforms. On these platforms, in BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, FPS, GTM, Link Controller, PEM, WebAccelerator) versions 14.0.0-14.1.0.1, 13.0.0-13.1.1.3, and 12.1.1 HF2-12.1.4, the secureKeyCapable attribute was not set which causes secure vault to not use the F5 hardware support to store the unit key. Instead the unit key is stored in plaintext on disk as would be the case for Z100 systems. Additionally this causes the unit key to be stored in UCS files taken on these platforms.
Published 2019-04-15 · Modified
9.8EPSS 0.015
CVE-2018-5506
In F5 BIG-IP 13.0.0, 12.1.0-12.1.2, 11.6.1, 11.5.1-11.5.5, or 11.2.1 the Apache modules apache_auth_token_mod and mod_auth_f5_auth_token.cpp allow possible unauthenticated bruteforce on the em_server_ip authorization parameter to obtain which SSL client certificates used for mutual authentication between BIG-IQ or Enterprise Manager (EM) and managed BIG-IP devices.
Published 2018-04-13 · Modified
9.8EPSS 0.007
CVE-2019-6644
Similar to the issue identified in CVE-2018-12120, on versions 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.2, and 12.1.0-12.1.4 BIG-IP will bind a debug nodejs process to all interfaces when invoked. This may expose the process to unauthorized users if the plugin is left in debug mode and the port is accessible.
Published 2019-09-04 · Modified
9.4EPSS 0.014
CVE-2013-0150
Directory traversal vulnerability in an unspecified signed Java applet in the client-side components in F5 BIG-IP APM 10.1.0 through 10.2.4 and 11.0.0 through 11.3.0, FirePass 6.0.0 through 6.1.0 and 7.0.0, and other products "when APM is provisioned," allows remote attackers to upload and execute arbitrary files via a .. (dot dot) in the filename parameter.
Published 2013-08-09 · Modified
9.3EPSS 0.063
CVE-2018-5504
In some circumstances, the Traffic Management Microkernel (TMM) does not properly handle certain malformed Websockets requests/responses, which allows remote attackers to cause a denial-of-service (DoS) or possible remote code execution on the F5 BIG-IP system running versions 13.0.0 - 13.1.0.3 or 12.1.0 - 12.1.3.1.
Published 2018-03-22 · Modified
9.3EPSS 0.043
CVE-2011-3188
The (1) IPv4 and (2) IPv6 implementations in the Linux kernel before 3.1 use a modified MD4 algorithm to generate sequence numbers and Fragment Identification values, which makes it easier for remote attackers to cause a denial of service (disrupted networking) or hijack network sessions by predicting these values and sending crafted packets.
Published 2012-05-24 · Modified
9.1EPSS 0.051
CVE-2019-10744
Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.
Published 2019-07-25 · Modified
9.1EPSS 0.050
CVE-2020-5887
On versions 15.1.0-15.1.0.1, 15.0.0-15.0.1.2, and 14.1.0-14.1.2.3, BIG-IP Virtual Edition (VE) may expose a mechanism for remote attackers to access local daemons and bypass port lockdown settings.
Published 2020-04-30 · Modified
9.1EPSS 0.018
CVE-2019-6649
F5 BIG-IP 15.0.0, 14.1.0-14.1.0.6, 14.0.0-14.0.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, 11.6.0-11.6.4, and 11.5.1-11.5.9 and Enterprise Manager 3.1.1 may expose sensitive information and allow the system configuration to be modified when using non-default ConfigSync settings.
Published 2019-09-20 · Modified
9.1EPSS 0.013
CVE-2019-6592
On BIG-IP 14.1.0-14.1.0.1, TMM may restart and produce a core file when validating SSL certificates in client SSL or server SSL profiles.
Published 2019-02-26 · Modified
9.1EPSS 0.010
CVE-2026-41225
iControl REST vulnerability
Published 2026-05-13 · Analyzed
9.1EPSS 0.005
CVE-2012-3163
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Information Schema.
Published 2012-10-17 · Modified
9.0EPSS 0.051
CVE-2019-6642
In BIG-IP 15.0.0, 14.0.0-14.1.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.2, and 11.5.2-11.6.4, BIG-IQ 6.0.0-6.1.0 and 5.1.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1, authenticated users with the ability to upload files (via scp, for example) can escalate their privileges to allow root shell access from within the TMOS Shell (tmsh) interface. The tmsh interface allows users to execute a secondary program via tools like sftp or scp.
Published 2019-07-01 · Modified
9.0EPSS 0.018
CVE-2025-20058
BIG-IP message routing vulnerability
Published 2025-02-05 · Analyzed
8.9EPSS 0.004
CVE-2025-21087
TMM Vulnerability
Published 2025-02-05 · Analyzed
8.9EPSS 0.004
CVE-2025-20029
BIG-IP iControl REST and tmsh vulnerability
Published 2025-02-05 · Analyzed
8.8EPSS 0.072
CVE-2019-6646
On BIG-IP 11.5.2-11.6.4 and Enterprise Manager 3.1.1, REST users with guest privileges may be able to escalate their privileges and run commands with admin privileges.
Published 2019-09-04 · Modified
8.8EPSS 0.015
CVE-2026-41957
BIG-IP and BIG-IQ Configuration utility vulnerability
Published 2026-05-13 · Analyzed
8.8EPSS 0.009
CVE-2025-31644
Appliance mode BIG-IP iControl REST and tmsh vulnerability
Published 2025-05-07 · Analyzed
8.7EPSS 0.265
CVE-2026-34176
Knowledge Appliance mode iControl REST vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.009
CVE-2026-42930
Appliance mode iControl REST vulnerability
Published 2026-05-13 · Undergoing Analysis
8.7EPSS 0.006
CVE-2026-39455
BIG-IP Configuration utility vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.005
CVE-2024-39778
BIG-IP HSB vulnerability
Published 2024-08-14 · Analyzed
8.7EPSS 0.005
CVE-2024-41727
BIG-IP TMM vulnerability
Published 2024-08-14 · Analyzed
8.7EPSS 0.005
CVE-2026-41956
BIG-IP TMM Vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.005
CVE-2026-40423
BIG-IP SIP profile vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.005
CVE-2026-40629
BIG-IP SSL/TLS vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.005
CVE-2026-41218
BIG-IP PEM iRules vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.005
CVE-2026-40618
BIG-IP SSL/TLS vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.005
CVE-2026-39458
BIG-IP DNS Cache vulnerability
Published 2026-05-13 · Modified
8.7EPSS 0.005
CVE-2026-42920
BIG-IP DTLS Vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.005
CVE-2026-42409
BIG-IP HTTP/2 vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.005
CVE-2025-21091
BIG-IP SNMP vulnerability
Published 2025-02-05 · Analyzed
8.7EPSS 0.005
CVE-2025-48008
BIG-IP MPTCP vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.004
CVE-2025-53868
BIG-IP SCP and SFTP vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.004
CVE-2025-46706
BIG-IP iRules vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.004
CVE-2025-36504
BIG-IP HTTP/2 vulnerability
Published 2025-05-07 · Analyzed
8.7EPSS 0.004
CVE-2025-41433
BIG-IP SIP ALG profile vulnerability
Published 2025-05-07 · Analyzed
8.7EPSS 0.004
1 / 7Next →