VendorsF5big-ip_websafeall versions
Vulnerabilities

F5 Big-IP WebSafe

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

175CVEs
CVE-2023-41373
BIG-IP Configuration Utility vulnerability
Published 2023-10-10 · Modified
9.9EPSS 0.024
CVE-2023-46747
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
Published 2023-10-26 · Analyzed
9.8KEVEPSS 0.965
CVE-2016-5700
Virtual servers in F5 BIG-IP systems 11.5.0, 11.5.1 before HF11, 11.5.2, 11.5.3, 11.5.4 before HF2, 11.6.0 before HF8, 11.6.1 before HF1, 12.0.0 before HF4, and 12.1.0 before HF2, when configured with the HTTP Explicit Proxy functionality or SOCKS profile, allow remote attackers to modify the system configuration, read system files, and possibly execute arbitrary code via unspecified vectors.
Published 2016-10-03 · Modified
9.8EPSS 0.064
CVE-2017-6165
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM, and WebSafe 11.5.1 HF6 through 11.5.4 HF4, 11.6.0 through 11.6.1 HF1, and 12.0.0 through 12.1.2 on VIPRION platforms only, the script which synchronizes SafeNet External Network HSM configuration elements between blades in a clustered deployment will log the HSM partition password in cleartext to the "/var/log/ltm" log file.
Published 2017-10-20 · Modified
9.8EPSS 0.019
CVE-2017-6131
In some circumstances, an F5 BIG-IP version 12.0.0 to 12.1.2 and 13.0.0 Azure cloud instance may contain a default administrative password which could be used to remotely log into the BIG-IP system. The impacted administrative account is the Azure instance administrative user that was created at deployment. The root and admin accounts are not vulnerable. An attacker may be able to remotely access the BIG-IP host via SSH.
Published 2017-05-23 · Modified
9.8EPSS 0.011
CVE-2018-5506
In F5 BIG-IP 13.0.0, 12.1.0-12.1.2, 11.6.1, 11.5.1-11.5.5, or 11.2.1 the Apache modules apache_auth_token_mod and mod_auth_f5_auth_token.cpp allow possible unauthenticated bruteforce on the em_server_ip authorization parameter to obtain which SSL client certificates used for mutual authentication between BIG-IQ or Enterprise Manager (EM) and managed BIG-IP devices.
Published 2018-04-13 · Modified
9.8EPSS 0.007
CVE-2018-5504
In some circumstances, the Traffic Management Microkernel (TMM) does not properly handle certain malformed Websockets requests/responses, which allows remote attackers to cause a denial-of-service (DoS) or possible remote code execution on the F5 BIG-IP system running versions 13.0.0 - 13.1.0.3 or 12.1.0 - 12.1.3.1.
Published 2018-03-22 · Modified
9.3EPSS 0.043
CVE-2026-41225
iControl REST vulnerability
Published 2026-05-13 · Analyzed
9.1EPSS 0.005
CVE-2025-21087
TMM Vulnerability
Published 2025-02-05 · Analyzed
8.9EPSS 0.004
CVE-2025-20058
BIG-IP message routing vulnerability
Published 2025-02-05 · Analyzed
8.9EPSS 0.004
CVE-2025-20029
BIG-IP iControl REST and tmsh vulnerability
Published 2025-02-05 · Analyzed
8.8EPSS 0.072
CVE-2023-46748
BIG-IP Configuration utility authenticated SQL injection vulnerability
Published 2023-10-26 · Analyzed
8.8KEVEPSS 0.045
CVE-2016-9251
In F5 BIG-IP 12.0.0 through 12.1.2, an authenticated attacker may be able to cause an escalation of privileges through a crafted iControl REST connection.
Published 2017-05-09 · Modified
8.8EPSS 0.015
CVE-2026-41957
BIG-IP and BIG-IQ Configuration utility vulnerability
Published 2026-05-13 · Analyzed
8.8EPSS 0.009
CVE-2025-31644
Appliance mode BIG-IP iControl REST and tmsh vulnerability
Published 2025-05-07 · Analyzed
8.7EPSS 0.265
CVE-2026-34176
Knowledge Appliance mode iControl REST vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.009
CVE-2026-42930
Appliance mode iControl REST vulnerability
Published 2026-05-13 · Undergoing Analysis
8.7EPSS 0.006
CVE-2026-39455
BIG-IP Configuration utility vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.005
CVE-2024-41727
BIG-IP TMM vulnerability
Published 2024-08-14 · Analyzed
8.7EPSS 0.005
CVE-2024-39778
BIG-IP HSB vulnerability
Published 2024-08-14 · Analyzed
8.7EPSS 0.005
CVE-2026-41218
BIG-IP PEM iRules vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.005
CVE-2026-42409
BIG-IP HTTP/2 vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.005
CVE-2026-40629
BIG-IP SSL/TLS vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.005
CVE-2026-42920
BIG-IP DTLS Vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.005
CVE-2026-39458
BIG-IP DNS Cache vulnerability
Published 2026-05-13 · Modified
8.7EPSS 0.005
CVE-2026-41956
BIG-IP TMM Vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.005
CVE-2026-40423
BIG-IP SIP profile vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.005
CVE-2026-40618
BIG-IP SSL/TLS vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.005
CVE-2025-21091
BIG-IP SNMP vulnerability
Published 2025-02-05 · Analyzed
8.7EPSS 0.005
CVE-2025-48008
BIG-IP MPTCP vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.004
CVE-2025-53868
BIG-IP SCP and SFTP vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.004
CVE-2023-43746
BIG-IP Appliance mode external monitor vulnerability
Published 2023-10-10 · Modified
8.7EPSS 0.004
CVE-2025-46706
BIG-IP iRules vulnerability
Published 2025-10-15 · Analyzed
8.7EPSS 0.004
CVE-2025-36504
BIG-IP HTTP/2 vulnerability
Published 2025-05-07 · Analyzed
8.7EPSS 0.004
CVE-2025-41433
BIG-IP SIP ALG profile vulnerability
Published 2025-05-07 · Analyzed
8.7EPSS 0.004
CVE-2025-41414
BIG-IP HTTP/2 vulnerability
Published 2025-05-07 · Analyzed
8.7EPSS 0.004
CVE-2025-41399
SCTP Vulnerability
Published 2025-05-07 · Analyzed
8.7EPSS 0.004
CVE-2026-42924
BIG-IP iControl SOAP vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.004
CVE-2026-40698
iControl REST and TMSH vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.004
CVE-2026-40631
BIG-IP iControl SOAP vulnerability
Published 2026-05-13 · Analyzed
8.7EPSS 0.004
1 / 5Next →