VendorsF5big-iq_centralized_management7.1.0
Vulnerabilities

F5 Big-iq Centralized Management 7.1.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2022-35728
iControl REST vulnerability CVE-2022-35728
Published 2022-08-04 · Modified
9.8EPSS 0.007
CVE-2022-41622
iControl SOAP vulnerability
Published 2022-12-07 · Modified
8.8EPSS 0.923
CVE-2002-20001
The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network bandwidth. The attack may be more disruptive in cases where a client can require a server to select its largest supported key size. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE.
Published 2021-11-11 · Analyzed
7.5EPSS 0.246
CVE-2022-34844
BIG-IP and BIG-IQ AWS vulnerability CVE-2022-34844
Published 2022-08-04 · Modified
7.5EPSS 0.007
CVE-2022-41770
BIG-IP and BIG-IQ iControl REST vulnerability CVE-2022-41770
Published 2022-10-19 · Modified
6.5EPSS 0.006
CVE-2022-29479
On F5 BIG-IP 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, and F5 BIG-IQ Centralized Management all versions of 8.x and 7.x, when an IPv6 self IP address is configured and the ipv6.strictcompliance database key is enabled (disabled by default) on a BIG-IP system, undisclosed packets may cause decreased performance. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Published 2022-05-05 · Modified
5.3EPSS 0.009