VendorsF5big-ip_websafeany version
Vulnerabilities

F5 Big-IP WebSafe any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

140CVEs
CVE-2023-29163
BIG-IP UDP Profile vulnerability
Published 2023-05-03 · Modified
7.5EPSS 0.006
CVE-2023-40534
BIG-IP HTTP/2 vulnerability
Published 2023-10-10 · Modified
7.5EPSS 0.005
CVE-2023-40542
BIG-IP TCP Profile vulnerability
Published 2023-10-10 · Analyzed
7.5EPSS 0.005
CVE-2024-25560
TMM Vulnerability
Published 2024-05-08 · Analyzed
7.5EPSS 0.005
CVE-2023-41085
BIG-IP IPSEC vulnerability
Published 2023-10-10 · Modified
7.5EPSS 0.005
CVE-2023-27378
BIG-IP TMUI XSS vulnerability
Published 2023-05-03 · Modified
7.5EPSS 0.004
CVE-2023-38138
BIG-IP Configuration utility vulnerability
Published 2023-08-02 · Modified
7.5EPSS 0.004
CVE-2023-42768
BIG-IP iControl REST vulnerability
Published 2023-10-10 · Modified
7.2EPSS 0.005
CVE-2026-42919
F5 BIG-IP Appliance Mode Vulnerability
Published 2026-05-13 · Analyzed
7.1EPSS 0.004
CVE-2026-40699
BIG-IP Configuration utility vulnerability
Published 2026-05-13 · Analyzed
7.1EPSS 0.004
CVE-2026-41219
BIG-IP QKView vulnerability
Published 2026-05-13 · Analyzed
7.1EPSS 0.004
CVE-2026-35062
iControl SOAP vulnerability
Published 2026-05-13 · Analyzed
7.1EPSS 0.003
CVE-2026-40462
iControl REST and tmsh vulnerability
Published 2026-05-13 · Analyzed
7.1EPSS 0.003
CVE-2026-41959
iControl and tmsh REST vulnerability
Published 2026-05-13 · Analyzed
7.1EPSS 0.003
CVE-2026-42937
iControl REST and tmsh vulnerability
Published 2026-05-13 · Analyzed
7.1EPSS 0.003
CVE-2026-42781
BIG-IP FastL4 virtual server vulnerability
Published 2026-05-13 · Analyzed
7.1EPSS 0.003
CVE-2025-54755
BIG-IP Configuration utility vulnerability
Published 2025-10-15 · Analyzed
6.9EPSS 0.012
CVE-2026-24464
Appliance mode iControl REST vulnerability
Published 2026-05-13 · Analyzed
6.9EPSS 0.009
CVE-2025-54500
HTTP/2 Vulnerability
Published 2025-08-13 · Analyzed
6.9EPSS 0.005
CVE-2025-59268
BIG-IP Configuration utility vulnerability
Published 2025-10-15 · Analyzed
6.9EPSS 0.004
CVE-2026-41954
iControl REST and tmsh vulnerability
Published 2026-05-13 · Analyzed
6.9EPSS 0.004
CVE-2026-42063
iControl SOAP vulnerability
Published 2026-05-13 · Analyzed
6.9EPSS 0.004
CVE-2026-40435
BIG-IP httpd access control vulnerability
Published 2026-05-13 · Analyzed
6.9EPSS 0.003
CVE-2026-42408
BIG-IP DNS tmsh vulnerability
Published 2026-05-13 · Analyzed
6.7EPSS 0.001
CVE-2017-6158
In F5 BIG-IP 12.0.0-12.1.2, 11.6.0-11.6.1, 11.5.1-11.5.5, or 11.2.1 there is a vulnerability in TMM related to handling of invalid IP addresses.
Published 2018-04-13 · Modified
6.5EPSS 0.011
CVE-2017-6134
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and WebSafe software version 13.0.0, 12.1.0 - 12.1.2 and 11.5.1 - 11.6.1, an undisclosed sequence of packets, sourced from an adjacent network may cause TMM to crash.
Published 2017-12-21 · Modified
6.5EPSS 0.009
CVE-2024-32761
BIG-IP TMM tenants on VELOS and rSeries vulnerability
Published 2024-05-08 · Analyzed
6.5EPSS 0.005
CVE-2023-41964
BIG-IP and BIG-IQ Database Variable vulnerability
Published 2023-10-10 · Modified
6.5EPSS 0.002
CVE-2017-6156
When the F5 BIG-IP 12.1.0-12.1.1, 11.6.0-11.6.1, 11.5.1-11.5.5, or 11.2.1 system is configured with a wildcard IPSec tunnel endpoint, it may allow a remote attacker to disrupt or impersonate the tunnels that have completed phase 1 IPSec negotiations. The attacker must possess the necessary credentials to negotiate the phase 1 of the IPSec exchange to exploit this vulnerability; in many environment this limits the attack surface to other endpoints under the same administration.
Published 2018-04-13 · Modified
6.4EPSS 0.009
CVE-2018-5515
On F5 BIG-IP 13.0.0-13.1.0.5, using RADIUS authentication responses from a RADIUS server with IPv6 addresses may cause TMM to crash, leading to a failover event.
Published 2018-05-02 · Modified
6.3EPSS 0.032
CVE-2026-34019
BIG-IP BFD vulnerability
Published 2026-05-13 · Analyzed
6.3EPSS 0.004
CVE-2025-58424
BIG-IP TMM vulnerability
Published 2025-10-15 · Analyzed
6.3EPSS 0.002
CVE-2018-5521
On F5 BIG-IP 12.1.0-12.1.3.1, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, carefully crafted URLs can be used to reflect arbitrary content into GeoIP lookup responses, potentially exposing clients to XSS.
Published 2018-06-01 · Modified
6.1EPSS 0.009
CVE-2019-6625
On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, and 11.5.1-11.6.4, a reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Traffic Management User Interface (TMUI) also known as the BIG-IP Configuration utility.
Published 2019-07-03 · Modified
6.1EPSS 0.008
CVE-2024-33604
BIG-IP Configuration utility XSS vulnerability
Published 2024-05-08 · Analyzed
6.1EPSS 0.003
CVE-2023-3470
BIG-IP FIPS HSM password vulnerability CVE-2023-3470
Published 2023-08-02 · Modified
6.1EPSS 0.002
CVE-2018-5522
On F5 BIG-IP 13.0.0, 12.0.0-12.1.2, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, when processing DIAMETER transactions with carefully crafted attribute-value pairs, TMM may crash.
Published 2018-06-01 · Modified
5.9EPSS 0.015
CVE-2017-6136
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and WebSafe software version 13.0.0 and 12.0.0 - 12.1.2, undisclosed traffic patterns sent to BIG-IP virtual servers, with the TCP Fast Open and Tail Loss Probe options enabled in the associated TCP profile, may cause a disruption of service to the Traffic Management Microkernel (TMM).
Published 2017-12-21 · Modified
5.9EPSS 0.014
CVE-2018-5500
On F5 BIG-IP systems running 13.0.0, 12.1.0 - 12.1.3.1, or 11.6.1 - 11.6.2, every Multipath TCP (MCTCP) connection established leaks a small amount of memory. Virtual server using TCP profile with Multipath TCP (MCTCP) feature enabled will be affected by this issue.
Published 2018-03-01 · Modified
5.9EPSS 0.013
CVE-2018-5501
In some circumstances, on F5 BIG-IP systems running 13.0.0, 12.1.0 - 12.1.3.1, any 11.6.x or 11.5.x release, or 11.2.1, TCP DNS profile allows excessive buffering due to lack of flow control.
Published 2018-03-01 · Modified
5.9EPSS 0.013
← Prev3 / 4Next →