VendorsF5big-ip_fraud_protection_serviceany version
Vulnerabilities

F5 Big-ip Fraud Protection Service any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

372CVEs
CVE-2022-23021
On BIG-IP version 16.1.x before 16.1.2, when any of the following configurations are configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate: HTTP redirect rule in an LTM policy, BIG-IP APM Access Profile, and Explicit HTTP Proxy in HTTP Profile. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published 2022-01-25 · Modified
7.5EPSS 0.009
CVE-2022-23022
On BIG-IP version 16.1.x before 16.1.2, when an HTTP profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published 2022-01-25 · Modified
7.5EPSS 0.009
CVE-2022-23016
On versions 16.1.x before 16.1.2 and 15.1.x before 15.1.4.1, when BIG-IP SSL Forward Proxy with TLS 1.3 is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published 2022-01-25 · Modified
7.5EPSS 0.009
CVE-2022-23025
On BIG-IP version 16.1.x before 16.1.1, 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, and all versions of 13.1.x, when a SIP ALG profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published 2022-01-25 · Modified
7.5EPSS 0.009
CVE-2019-6664
On BIG-IP 15.0.0 and 14.1.0-14.1.0.6, under certain conditions, network protections on the management port do not follow current best practices.
Published 2019-11-15 · Modified
7.5EPSS 0.009
CVE-2021-23013
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, the Traffic Management Microkernel (TMM) may stop responding when processing Stream Control Transmission Protocol (SCTP) traffic under certain conditions. This vulnerability affects TMM by way of a virtual server configured with an SCTP profile. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published 2021-05-10 · Modified
7.5EPSS 0.009
CVE-2021-22974
On BIG-IP version 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, and 13.1.x before 13.1.3.6 and all versions of BIG-IQ 7.x and 6.x, an authenticated attacker with access to iControl REST over the control plane may be able to take advantage of a race condition to execute commands with an elevated privilege level. This vulnerability is due to an incomplete fix for CVE-2017-6167. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Published 2021-02-12 · Modified
7.5EPSS 0.008
CVE-2022-34651
BIG-IP TLS 1.3 iRule vulnerability CVE-2022-34651
Published 2022-08-04 · Modified
7.5EPSS 0.007
CVE-2022-34655
TMM vulnerability CVE-2022-34655
Published 2022-08-04 · Modified
7.5EPSS 0.007
CVE-2022-35236
HTTP2 profile vulnerability CVE-2022-35236
Published 2022-08-04 · Modified
7.5EPSS 0.007
CVE-2022-35240
BIG-IP Message Routing MQTT vulnerability CVE-2022-35240
Published 2022-08-04 · Modified
7.5EPSS 0.007
CVE-2022-34844
BIG-IP and BIG-IQ AWS vulnerability CVE-2022-34844
Published 2022-08-04 · Modified
7.5EPSS 0.007
CVE-2022-41832
BIG-IP SIP vulnerability CVE-2022-41832
Published 2022-10-19 · Modified
7.5EPSS 0.007
CVE-2022-41624
BIG-IP iRules vulnerability CVE-2022-41624
Published 2022-10-19 · Modified
7.5EPSS 0.007
CVE-2022-36795
BIG-IP software SYN cookies vulnerability CVE-2022-36795
Published 2022-10-19 · Modified
7.5EPSS 0.007
CVE-2022-41833
BIG-IP iRule vulnerability CVE-2022-41833
Published 2022-10-19 · Modified
7.5EPSS 0.007
CVE-2023-22323
BIG-IP SSL OCSP Authentication profile vulnerability
Published 2023-02-01 · Modified
7.5EPSS 0.007
CVE-2022-23015
On BIG-IP versions 16.x before 16.1.0, 15.1.x before 15.1.4.1, and 14.1.2.6-14.1.4.4, when a Client SSL profile is configured on a virtual server with Client Certificate Authentication set to request/require and Session Ticket enabled and configured, processing SSL traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published 2022-01-25 · Modified
7.5EPSS 0.006
CVE-2023-23555
BIG-IP Virtual Edition vulnerability
Published 2023-02-01 · Modified
7.5EPSS 0.006
CVE-2023-22842
BIG-IP SIP profile vulnerability
Published 2023-02-01 · Modified
7.5EPSS 0.006
CVE-2023-22664
BIG-IP HTTP/2 profile vulnerability
Published 2023-02-01 · Modified
7.5EPSS 0.006
CVE-2023-22422
HTTP profile vulnerability
Published 2023-02-01 · Modified
7.5EPSS 0.006
CVE-2023-22340
BIG-IP SIP profile vulnerability
Published 2023-02-01 · Modified
7.5EPSS 0.006
CVE-2023-29163
BIG-IP UDP Profile vulnerability
Published 2023-05-03 · Modified
7.5EPSS 0.006
CVE-2023-40534
BIG-IP HTTP/2 vulnerability
Published 2023-10-10 · Modified
7.5EPSS 0.005
CVE-2023-40542
BIG-IP TCP Profile vulnerability
Published 2023-10-10 · Analyzed
7.5EPSS 0.005
CVE-2024-25560
TMM Vulnerability
Published 2024-05-08 · Analyzed
7.5EPSS 0.005
CVE-2024-24775
BIG-IP TMM vulnerability
Published 2024-02-14 · Analyzed
7.5EPSS 0.005
CVE-2023-41085
BIG-IP IPSEC vulnerability
Published 2023-10-10 · Modified
7.5EPSS 0.005
CVE-2024-23314
BIG-IP HTTP/2 vulnerability
Published 2024-02-14 · Analyzed
7.5EPSS 0.005
CVE-2022-32455
TMM vulnerability CVE-2022-32455
Published 2022-08-04 · Modified
7.5EPSS 0.005
CVE-2022-35272
BIG-IP HTTP MRF vulnerability CVE-2022-35272
Published 2022-08-04 · Modified
7.5EPSS 0.005
CVE-2023-38138
BIG-IP Configuration utility vulnerability
Published 2023-08-02 · Modified
7.5EPSS 0.004
CVE-2023-27378
BIG-IP TMUI XSS vulnerability
Published 2023-05-03 · Modified
7.5EPSS 0.004
CVE-2024-23979
BIG-IP SSL Client Certificate LDAP and CRLDP Authentication profiles vulnerability
Published 2024-02-14 · Analyzed
7.5EPSS 0.003
CVE-2018-5531
Through undisclosed methods, on F5 BIG-IP 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, 11.6.0-11.6.3.1, or 11.2.1-11.5.6, adjacent network attackers can cause a denial of service for VCMP guest and host systems. Attack must be sourced from adjacent network (layer 2).
Published 2018-07-25 · Modified
7.4EPSS 0.005
CVE-2020-5913
In versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2, the BIG-IP Client or Server SSL profile ignores revoked certificates, even when a valid CRL is present. This impacts SSL/TLS connections and may result in a man-in-the-middle attack on the connections.
Published 2020-08-26 · Modified
7.4EPSS 0.005
CVE-2018-5523
On F5 BIG-IP 13.1.0-13.1.0.3, 13.0.0, 12.1.0-12.1.3.1, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1 and Enterprise Manager 3.1.1, when authenticated administrative users run commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, restrictions on allowed commands may not be enforced.
Published 2018-06-01 · Modified
7.2EPSS 0.022
CVE-2019-6621
On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4.1, 11.6.1-11.6.3.4, and 11.5.2-11.5.8 and BIG-IQ 7.0.0-7.1.0.2, 6.0.0-6.1.0, and 5.1.0-5.4.0, an undisclosed iControl REST worker is vulnerable to command injection by an admin/resource admin user. This issue impacts both iControl REST and tmsh implementations.
Published 2019-07-02 · Modified
7.2EPSS 0.020
CVE-2019-6620
On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.5, 13.0.0-13.1.1.4, 12.1.0-12.1.4.1, and 11.5.1-11.6.4 and BIG-IQ 6.0.0-6.1.0 and 5.1.0-5.4.0, an undisclosed iControl REST worker vulnerable to command injection for an Administrator user.
Published 2019-07-02 · Modified
7.2EPSS 0.018
← Prev6 / 10Next →