VendorsF5big-ip_websafeall versions
Vulnerabilities

F5 Big-IP WebSafe

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

175CVEs
CVE-2018-5514
On F5 BIG-IP 13.1.0-13.1.0.5, maliciously crafted HTTP/2 request frames can lead to denial of service. There is data plane exposure for virtual servers when the HTTP2 profile is enabled. There is no control plane exposure to this issue.
Published 2018-05-02 · Modified
7.5EPSS 0.039
CVE-2017-0303
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and Websafe software version 13.0.0, 12.0.0 to 12.1.2 and 11.5.1 to 11.6.1, under limited circumstances connections handled by a Virtual Server with an associated SOCKS profile may not be properly cleaned up, potentially leading to resource starvation. Connections may be left in the connection table which then can only be removed by restarting TMM. Over time this may lead to the BIG-IP being unable to process further connections.
Published 2017-10-27 · Modified
7.5EPSS 0.027
CVE-2017-6132
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and Websafe software version 13.0.0, 12.0.0 to 12.1.2, 11.6.0 to 11.6.1 and 11.5.0 - 11.5.4, an undisclosed sequence of packets sent to BIG-IP High Availability state mirror listeners (primary and/or secondary IP) may cause TMM to restart.
Published 2017-12-21 · Modified
7.5EPSS 0.025
CVE-2019-6631
On BIG-IP 11.5.1-11.6.4, iRules performing HTTP header manipulation may cause an interruption to service when processing traffic handled by a Virtual Server with an associated HTTP profile, in specific circumstances, when the requests do not strictly conform to RFCs.
Published 2019-07-03 · Modified
7.5EPSS 0.025
CVE-2016-7476
The Traffic Management Microkernel (TMM) in F5 BIG-IP LTM, AAM, AFM, APM, ASM, GTM, Link Controller, PEM, PSM, and WebSafe 11.6.0 before 11.6.0 HF6, 11.5.0 before 11.5.3 HF2, and 11.3.0 before 11.4.1 HF10 may suffer from a memory leak while handling certain types of TCP traffic. Remote attackers may cause a denial of service (DoS) by way of a crafted TCP packet.
Published 2017-05-11 · Modified
7.5EPSS 0.024
CVE-2016-5736
The default configuration of the IPsec IKE peer listener in F5 BIG-IP LTM, Analytics, APM, ASM, and Link Controller 11.2.1 before HF16, 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.6.1, and 12.x before 12.0.0 HF2; BIG-IP AAM, AFM, and PEM 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.6.1, and 12.x before 12.0.0 HF2; BIG-IP DNS 12.x before 12.0.0 HF2; BIG-IP Edge Gateway, WebAccelerator, and WOM 11.2.1 before HF16; BIG-IP GTM 11.2.1 before HF16, 11.4.x, 11.5.x before 11.5.4 HF2, and 11.6.x before 11.6.1; and BIG-IP PSM 11.4.0 through 11.4.1 improperly enables the anonymous IPsec IKE peer configuration object, which allows remote attackers to establish an IKE Phase 1 negotiation and possibly conduct brute-force attacks against Phase 2 negotiations via unspecified vectors.
Published 2016-08-19 · Modified
7.5EPSS 0.023
CVE-2018-5530
F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.5, or 11.6.0-11.6.3.1 virtual servers with HTTP/2 profiles enabled are vulnerable to "HPACK Bomb".
Published 2018-07-25 · Modified
7.5EPSS 0.018
CVE-2016-9252
The Traffic Management Microkernel (TMM) in F5 BIG-IP before 11.5.4 HF3, 11.6.x before 11.6.1 HF2 and 12.x before 12.1.2 does not properly handle minimum path MTU options for IPv6, which allows remote attackers to cause a denial-of-service (DoS) through unspecified vectors.
Published 2017-03-27 · Modified
7.5EPSS 0.018
CVE-2018-5513
On F5 BIG-IP 13.1.0-13.1.0.3, 13.0.0, 12.1.0-12.1.3.3, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, a malformed TLS handshake causes TMM to crash leading to a disruption of service. This issue is only exposed on the data plane when Proxy SSL configuration is enabled. The control plane is not impacted by this issue.
Published 2018-06-01 · Modified
7.5EPSS 0.018
CVE-2018-5517
On F5 BIG-IP 13.1.0-13.1.0.5, malformed TCP packets sent to a self IP address or a FastL4 virtual server may cause an interruption of service. The control plane is not exposed to this issue. This issue impacts the data plane virtual servers and self IPs.
Published 2018-05-02 · Modified
7.5EPSS 0.017
CVE-2017-6138
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and WebSafe software version 13.0.0 and 12.1.0 - 12.1.2, malicious requests made to virtual servers with an HTTP profile can cause the TMM to restart. The issue is exposed with BIG-IP APM profiles, regardless of settings. The issue is also exposed with the non-default "normalize URI" configuration options used in iRules and/or BIG-IP LTM policies.
Published 2017-12-21 · Modified
7.5EPSS 0.016
CVE-2017-6128
An attacker may be able to cause a denial-of-service (DoS) attack against the sshd component in F5 BIG-IP, Enterprise Manager, BIG-IQ, and iWorkflow.
Published 2017-05-01 · Modified
7.5EPSS 0.014
CVE-2016-9253
In F5 BIG-IP 12.1.0 through 12.1.2, specific websocket traffic patterns may cause a disruption of service for virtual servers configured to use the websocket profile.
Published 2017-05-09 · Modified
7.5EPSS 0.013
CVE-2018-5502
On F5 BIG-IP versions 13.0.0 - 13.1.0.3, attackers may be able to disrupt services on the BIG-IP system with maliciously crafted client certificate. This vulnerability affects virtual servers associated with Client SSL profile which enables the use of client certificate authentication. Client certificate authentication is not enabled by default in Client SSL profile. There is no control plane exposure.
Published 2018-03-22 · Modified
7.5EPSS 0.013
CVE-2019-6629
On BIG-IP 14.1.0-14.1.0.5, undisclosed SSL traffic to a virtual server configured with a Client SSL profile may cause TMM to fail and restart. The Client SSL profile must have session tickets enabled and use DHE cipher suites to be affected. This only impacts the data plane, there is no impact to the control plane.
Published 2019-07-03 · Modified
7.5EPSS 0.013
CVE-2017-6155
On F5 BIG-IP 13.0.0, 12.0.0-12.1.3.1, 11.6.0-11.6.2, 11.4.1-11.5.5, or 11.2.1, malformed SPDY or HTTP/2 requests may result in a disruption of service to TMM. Data plane is only exposed when a SPDY or HTTP/2 profile is attached to a virtual server. There is no control plane exposure.
Published 2018-04-13 · Modified
7.5EPSS 0.013
CVE-2017-6148
Responses to SOCKS proxy requests made through F5 BIG-IP version 13.0.0, 12.0.0-12.1.3.1, 11.6.1-11.6.2, or 11.5.1-11.5.5 may cause a disruption of services provided by TMM. The data plane is impacted and exposed only when a SOCKS proxy profile is attached to a Virtual Server. The control plane is not impacted by this vulnerability.
Published 2018-04-13 · Modified
7.5EPSS 0.013
CVE-2018-5507
On F5 BIG-IP versions 13.0.0, 12.1.0-12.1.3.1, 11.6.1-11.6.2, or 11.5.1-11.5.5, vCMP guests running on VIPRION 2100, 4200 and 4300 series blades cannot correctly decrypt ciphertext from established SSL sessions with small MTU.
Published 2018-04-13 · Modified
7.5EPSS 0.011
CVE-2017-6145
iControl REST in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe 12.0.0 through 12.1.2 and 13.0.0 includes a service to convert authorization BIGIPAuthCookie cookies to X-F5-Auth-Token tokens. This service does not properly re-validate cookies when making that conversion, allowing once-valid but now expired cookies to be converted to valid tokens.
Published 2017-10-20 · Modified
7.5EPSS 0.011
CVE-2016-9256
In F5 BIG-IP 12.1.0 through 12.1.2, permissions enforced by iControl can lag behind the actual permissions assigned to a user if the role_map is not reloaded between the time the permissions are changed and the time of the user's next request. This is a race condition that occurs rarely in normal usage; the typical period in which this is possible is limited to at most a few seconds after the permission change.
Published 2017-05-09 · Modified
7.5EPSS 0.010
CVE-2018-5510
On F5 BIG-IP 11.5.4 HF4-11.5.5, the Traffic Management Microkernel (TMM) may restart when processing a specific sequence of packets on IPv6 virtual servers.
Published 2018-04-13 · Modified
7.5EPSS 0.010
CVE-2016-9250
In F5 BIG-IP 11.2.1, 11.4.0 through 11.6.1, and 12.0.0 through 12.1.2, an unauthenticated user with access to the control plane may be able to delete arbitrary files through an undisclosed mechanism.
Published 2017-05-10 · Modified
7.5EPSS 0.009
CVE-2023-29163
BIG-IP UDP Profile vulnerability
Published 2023-05-03 · Modified
7.5EPSS 0.006
CVE-2024-33608
BIG-IP IPsec vulnerability
Published 2024-05-08 · Analyzed
7.5EPSS 0.006
CVE-2023-40534
BIG-IP HTTP/2 vulnerability
Published 2023-10-10 · Modified
7.5EPSS 0.005
CVE-2023-40542
BIG-IP TCP Profile vulnerability
Published 2023-10-10 · Analyzed
7.5EPSS 0.005
CVE-2024-25560
TMM Vulnerability
Published 2024-05-08 · Analyzed
7.5EPSS 0.005
CVE-2023-41085
BIG-IP IPSEC vulnerability
Published 2023-10-10 · Modified
7.5EPSS 0.005
CVE-2023-27378
BIG-IP TMUI XSS vulnerability
Published 2023-05-03 · Modified
7.5EPSS 0.004
CVE-2023-38138
BIG-IP Configuration utility vulnerability
Published 2023-08-02 · Modified
7.5EPSS 0.004
CVE-2018-5511
On F5 BIG-IP 13.1.0-13.1.0.3 or 13.0.0, when authenticated administrative users execute commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, restrictions on allowed commands may not be enforced.
Published 2018-04-13 · Modified
7.21 PoCEPSS 0.142
CVE-2023-42768
BIG-IP iControl REST vulnerability
Published 2023-10-10 · Modified
7.2EPSS 0.005
CVE-2026-42919
F5 BIG-IP Appliance Mode Vulnerability
Published 2026-05-13 · Analyzed
7.1EPSS 0.004
CVE-2026-40699
BIG-IP Configuration utility vulnerability
Published 2026-05-13 · Analyzed
7.1EPSS 0.004
CVE-2026-41219
BIG-IP QKView vulnerability
Published 2026-05-13 · Analyzed
7.1EPSS 0.004
CVE-2026-35062
iControl SOAP vulnerability
Published 2026-05-13 · Analyzed
7.1EPSS 0.003
CVE-2026-40462
iControl REST and tmsh vulnerability
Published 2026-05-13 · Analyzed
7.1EPSS 0.003
CVE-2026-41959
iControl and tmsh REST vulnerability
Published 2026-05-13 · Analyzed
7.1EPSS 0.003
CVE-2026-42937
iControl REST and tmsh vulnerability
Published 2026-05-13 · Analyzed
7.1EPSS 0.003
CVE-2026-42781
BIG-IP FastL4 virtual server vulnerability
Published 2026-05-13 · Analyzed
7.1EPSS 0.003
← Prev3 / 5Next →