VendorsF5big-ip_ssl_orchestratorall versions
Vulnerabilities

F5 Big-ip SSL Orchestrator

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

147CVEs
CVE-2022-33203
BIG-IP APM and F5 SSL Orchestrator vulnerability CVE-2022-33203
Published 2022-08-04 · Modified
7.5EPSS 0.007
CVE-2023-22323
BIG-IP SSL OCSP Authentication profile vulnerability
Published 2023-02-01 · Modified
7.5EPSS 0.007
CVE-2023-22422
HTTP profile vulnerability
Published 2023-02-01 · Modified
7.5EPSS 0.006
CVE-2023-22664
BIG-IP HTTP/2 profile vulnerability
Published 2023-02-01 · Modified
7.5EPSS 0.006
CVE-2023-22842
BIG-IP SIP profile vulnerability
Published 2023-02-01 · Modified
7.5EPSS 0.006
CVE-2023-23555
BIG-IP Virtual Edition vulnerability
Published 2023-02-01 · Modified
7.5EPSS 0.006
CVE-2023-22340
BIG-IP SIP profile vulnerability
Published 2023-02-01 · Modified
7.5EPSS 0.006
CVE-2023-29163
BIG-IP UDP Profile vulnerability
Published 2023-05-03 · Modified
7.5EPSS 0.006
CVE-2024-33608
BIG-IP IPsec vulnerability
Published 2024-05-08 · Analyzed
7.5EPSS 0.006
CVE-2023-40534
BIG-IP HTTP/2 vulnerability
Published 2023-10-10 · Modified
7.5EPSS 0.005
CVE-2023-40542
BIG-IP TCP Profile vulnerability
Published 2023-10-10 · Analyzed
7.5EPSS 0.005
CVE-2024-25560
TMM Vulnerability
Published 2024-05-08 · Analyzed
7.5EPSS 0.005
CVE-2023-41085
BIG-IP IPSEC vulnerability
Published 2023-10-10 · Modified
7.5EPSS 0.005
CVE-2023-27378
BIG-IP TMUI XSS vulnerability
Published 2023-05-03 · Modified
7.5EPSS 0.004
CVE-2023-38138
BIG-IP Configuration utility vulnerability
Published 2023-08-02 · Modified
7.5EPSS 0.004
CVE-2021-23015
On BIG-IP 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.0.8 through 13.1.3.6, and all versions of 16.0.x, when running in Appliance Mode, an authenticated user assigned the 'Administrator' role may be able to bypass Appliance Mode restrictions utilizing undisclosed iControl REST endpoints. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published 2021-05-10 · Modified
7.2EPSS 0.013
CVE-2023-42768
BIG-IP iControl REST vulnerability
Published 2023-10-10 · Modified
7.2EPSS 0.005
CVE-2026-42919
F5 BIG-IP Appliance Mode Vulnerability
Published 2026-05-13 · Analyzed
7.1EPSS 0.004
CVE-2025-47148
BIG-IP APM and SSL Orchestrator vulnerability
Published 2025-10-15 · Analyzed
7.1EPSS 0.004
CVE-2026-40699
BIG-IP Configuration utility vulnerability
Published 2026-05-13 · Analyzed
7.1EPSS 0.004
CVE-2026-41219
BIG-IP QKView vulnerability
Published 2026-05-13 · Analyzed
7.1EPSS 0.004
CVE-2026-35062
iControl SOAP vulnerability
Published 2026-05-13 · Analyzed
7.1EPSS 0.003
CVE-2026-40462
iControl REST and tmsh vulnerability
Published 2026-05-13 · Analyzed
7.1EPSS 0.003
CVE-2026-42937
iControl REST and tmsh vulnerability
Published 2026-05-13 · Analyzed
7.1EPSS 0.003
CVE-2026-41959
iControl and tmsh REST vulnerability
Published 2026-05-13 · Analyzed
7.1EPSS 0.003
CVE-2026-42781
BIG-IP FastL4 virtual server vulnerability
Published 2026-05-13 · Analyzed
7.1EPSS 0.003
CVE-2026-42780
BIG-IP SSL Orchestrator vulnerability
Published 2026-05-13 · Analyzed
6.9EPSS 0.012
CVE-2025-54755
BIG-IP Configuration utility vulnerability
Published 2025-10-15 · Analyzed
6.9EPSS 0.012
CVE-2026-24464
Appliance mode iControl REST vulnerability
Published 2026-05-13 · Analyzed
6.9EPSS 0.009
CVE-2025-54500
HTTP/2 Vulnerability
Published 2025-08-13 · Analyzed
6.9EPSS 0.005
CVE-2025-59268
BIG-IP Configuration utility vulnerability
Published 2025-10-15 · Analyzed
6.9EPSS 0.004
CVE-2026-41954
iControl REST and tmsh vulnerability
Published 2026-05-13 · Analyzed
6.9EPSS 0.004
CVE-2026-42063
iControl SOAP vulnerability
Published 2026-05-13 · Analyzed
6.9EPSS 0.004
CVE-2026-40435
BIG-IP httpd access control vulnerability
Published 2026-05-13 · Analyzed
6.9EPSS 0.003
CVE-2026-42408
BIG-IP DNS tmsh vulnerability
Published 2026-05-13 · Analyzed
6.7EPSS 0.001
CVE-2022-23023
On BIG-IP version 16.1.x before 16.1.2.1, 15.1.x before 15.1.5, 14.1.x before 14.1.4.5, and all versions of 13.1.x and 12.1.x, and BIG-IQ all versions of 8.x and 7.x, undisclosed requests by an authenticated iControl REST user can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published 2022-01-25 · Modified
6.5EPSS 0.009
CVE-2020-5943
In versions 14.1.0-14.1.0.1 and 14.1.2.5-14.1.2.7, when a BIG-IP object is created or listed through the REST interface, the protected fields are obfuscated in the REST response, not protected via a SecureVault cryptogram as TMSH does. One example of protected fields is the GTM monitor password.
Published 2020-11-05 · Modified
6.5EPSS 0.005
CVE-2024-32761
BIG-IP TMM tenants on VELOS and rSeries vulnerability
Published 2024-05-08 · Analyzed
6.5EPSS 0.005
CVE-2023-41964
BIG-IP and BIG-IQ Database Variable vulnerability
Published 2023-10-10 · Modified
6.5EPSS 0.002
CVE-2026-34019
BIG-IP BFD vulnerability
Published 2026-05-13 · Analyzed
6.3EPSS 0.004
← Prev3 / 4Next →