VYPR

Big IP

by F5, Inc.

CVEs (593)

  • CVE-2019-6595MedFeb 26, 2019
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in F5 BIG-IP Access Policy Manager (APM) 11.5.x and 11.6.x Admin Web UI.

  • CVE-2019-6589MedFeb 14, 2019
    risk 0.40cvss 6.1epss 0.01

    On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.3, 12.1.0-12.1.3.7, and 11.6.0-11.6.3.2, a reflected Cross Site Scripting (XSS) vulnerability is present in an undisclosed page of the BIG-IP TMUI (Traffic Management User Interface) also known as the BIG-IP configuration utility.

  • CVE-2018-15315MedOct 19, 2018
    risk 0.40cvss 6.1epss 0.01

    On F5 BIG-IP 13.0.0-13.1.1.1 and 12.1.0-12.1.3.6, there is a reflected Cross Site Scripting (XSS) vulnerability in an undisclosed Configuration Utility page.

  • CVE-2018-15312MedOct 19, 2018
    risk 0.40cvss 6.1epss 0.01

    On F5 BIG-IP 13.0.0-13.1.1.1 and 12.1.0-12.1.3.6, a reflected Cross-Site Scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an authenticated user to execute JavaScript for the currently logged-in user.

  • CVE-2018-5548MedSep 13, 2018
    risk 0.40cvss 6.1epss 0.01

    On BIG-IP APM 11.6.0-11.6.3, an insecure AES ECB mode is used for orig_uri parameter in an undisclosed /vdesk link of APM virtual server configured with an access profile, allowing a malicious user to build a redirect URI value using different blocks of cipher texts.

  • CVE-2018-5521MedJun 1, 2018
    risk 0.40cvss 6.1epss 0.01

    On F5 BIG-IP 12.1.0-12.1.3.1, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, carefully crafted URLs can be used to reflect arbitrary content into GeoIP lookup responses, potentially exposing clients to XSS.

  • CVE-2016-9257MedMay 9, 2017
    risk 0.40cvss 6.1epss 0.01

    In F5 BIG-IP APM 12.0.0 through 12.1.2, non-authenticated users may be able to inject JavaScript into a request that will then be rendered and executed in the context of the Administrative user when the Administrative user is viewing the Access System Logs, allowing the…

  • CVE-2024-23976MedFeb 14, 2024
    risk 0.39cvss 6.0epss 0.00

    When running in Appliance mode, an authenticated attacker assigned the Administrator role may be able to bypass Appliance mode restrictions utilizing iAppsLX templates on a BIG-IP system.  Note: Software versions which have reached End of Technical Support (EoTS) are not…

  • CVE-2023-3470MedAug 2, 2023
    risk 0.39cvss 6.0epss 0.00

    Specific F5 BIG-IP platforms with Cavium Nitrox FIPS HSM cards generate a deterministic password for the Crypto User account.  The predictable nature of the password allows an authenticated user with TMSH access to the BIG-IP system, or anyone with physical access to the FIPS…

  • CVE-2018-5505MedMar 22, 2018
    risk 0.39cvss 5.9epss 0.02

    On F5 BIG-IP versions 13.1.0 - 13.1.0.3, when ASM and AVR are both provisioned, TMM may restart while processing DNS requests when the virtual server is configured with a DNS profile and the Protocol setting is set to TCP.

  • CVE-2017-6160MedOct 27, 2017
    risk 0.39cvss 5.9epss 0.04

    In F5 BIG-IP AAM and PEM software version 12.0.0 to 12.1.1, 11.6.0 to 11.6.1, 11.4.1 to 11.5.4, a remote attacker may create maliciously crafted HTTP request to cause Traffic Management Microkernel (TMM) to restart and temporarily fail to process traffic. This issue is exposed…

  • CVE-2016-9247MedJan 10, 2017
    risk 0.39cvss 5.9epss 0.02

    Under certain conditions for BIG-IP systems using a virtual server with an associated FastL4 profile and TCP analytics profile, a specific sequence of packets may cause the Traffic Management Microkernel (TMM) to restart.

  • CVE-2015-8099MedMay 13, 2016
    risk 0.39cvss 5.9epss 0.02

    F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.x, 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, 11.6.x before 11.6.1, and 12.x before 12.0.0 HF1; BIG-IP AAM 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, 11.6.x before 11.6.1, and 12.x before 12.0.0…

  • CVE-2026-22548MedFeb 4, 2026
    risk 0.38cvss 5.9epss 0.00

    When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests along with conditions beyond the attacker's control can cause the bd process to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are…

  • CVE-2025-58153MedOct 15, 2025
    risk 0.38cvss 5.9epss 0.00

    Under undisclosed traffic conditions along with conditions beyond the attacker's control, hardware systems with a High-Speed Bridge (HSB) may experience a lockup of the HSB.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • CVE-2024-41164MedAug 14, 2024
    risk 0.38cvss 5.9epss 0.00

    When TCP profile with Multipath TCP enabled (MPTCP) is configured on a Virtual Server, undisclosed traffic along with conditions beyond the attackers control can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not…

  • CVE-2024-28889MedMay 8, 2024
    risk 0.38cvss 5.9epss 0.00

    When an SSL profile with alert timeout is configured with a non-default value on a virtual server, undisclosed traffic along with conditions beyond the attacker's control can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have…

  • CVE-2023-22302MedFeb 1, 2023
    risk 0.38cvss 5.9epss 0.01

    In BIG-IP versions 17.0.x before 17.0.0.2, and 16.1.x beginning in 16.1.2.2 to before 16.1.3.3, when an HTTP profile is configured on a virtual server and conditions beyond the attacker’s control exist on the target pool member, undisclosed requests sent to the BIG-IP system…

  • CVE-2022-34844MedAug 4, 2022
    risk 0.38cvss 5.9epss 0.01

    In BIG-IP Versions 16.1.x before 16.1.3.1 and 15.1.x before 15.1.6.1, and all versions of BIG-IQ 8.x, when the Data Plane Development Kit (DPDK)/Elastic Network Adapter (ENA) driver is used with BIG-IP or BIG-IQ on Amazon Web Services (AWS) systems, undisclosed traffic can cause…

  • CVE-2022-29473MedMay 5, 2022
    risk 0.38cvss 5.9epss 0.01

    On F5 BIG-IP 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, when an IPSec ALG profile is configured on a virtual server, undisclosed responses can cause Traffic Management Microkernel(TMM) to terminate. Note: Software…

Page 21 of 30