VYPR

BIG-IP Advanced WAF

by F5, Inc.

CVEs (12)

  • CVE-2026-40060HigMay 13, 2026
    risk 0.49cvss 7.5epss 0.00

    When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • CVE-2025-61938HigOct 15, 2025
    risk 0.49cvss 7.5epss 0.00

    When a BIG-IP Advanced WAF or ASM security policy is configured with a URL greater than 1024 characters in length for the Data Guard Protection Enforcement setting, either manually or through the automatic Policy Builder, the bd process can terminate repeatedly.  Note:…

  • CVE-2025-55669HigOct 15, 2025
    risk 0.49cvss 7.5epss 0.00

    When the BIG-IP Advanced WAF and ASM security policy and a server-side HTTP/2 profile are configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support…

  • CVE-2025-54858HigOct 15, 2025
    risk 0.49cvss 7.5epss 0.00

    When a BIG-IP Advanced WAF or BIG-IP ASM Security Policy is configured with a JSON content profile that has a malformed JSON schema, and the security policy is applied to a virtual server, undisclosed requests can cause the bd process to terminate.  Note: Software versions…

  • CVE-2024-23308HigFeb 14, 2024
    risk 0.49cvss 7.5epss 0.01

    When a BIG-IP Advanced WAF or BIG-IP ASM policy with a Request Body Handling option is attached to a virtual server, undisclosed requests can cause the BD process to terminate. The condition results from setting the Request Body Handling option in the Header-Based Content…

  • CVE-2022-41836HigOct 19, 2022
    risk 0.49cvss 7.5epss 0.01

    When an 'Attack Signature False Positive Mode' enabled security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate.

  • CVE-2022-41691HigOct 19, 2022
    risk 0.49cvss 7.5epss 0.01

    When a BIG-IP Advanced WAF/ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate.

  • CVE-2020-27718HigDec 24, 2020
    risk 0.49cvss 7.5epss 0.01

    When a BIG-IP ASM or Advanced WAF system running version 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, or 11.6.1-11.6.5.2 processes requests with JSON payload, an unusually large number of parameters can cause excessive CPU usage in the…

  • CVE-2020-5946HigNov 5, 2020
    risk 0.49cvss 7.5epss 0.01

    In BIG-IP Advanced WAF and FPS versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.2.7, under some circumstances, certain format client-side alerts sent to the BIG-IP virtual server configured with DataSafe may cause the Traffic Management Microkernel (TMM) to restart,…

  • CVE-2022-41617HigOct 19, 2022
    risk 0.47cvss 7.2epss 0.01

    In versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and 13.1.x before 13.1.5.1, When the Advanced WAF / ASM module is provisioned, an authenticated remote code execution vulnerability exists in the BIG-IP iControl REST interface.

  • CVE-2026-22548MedFeb 4, 2026
    risk 0.38cvss 5.9epss 0.00

    When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests along with conditions beyond the attacker's control can cause the bd process to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are…

  • CVE-2025-58474MedOct 15, 2025
    risk 0.34cvss 5.3epss 0.00

    When BIG-IP Advanced WAF is configured on a virtual server with Server-Side Request Forgery (SSRF) protection or when an NGINX server is configured with App Protect Bot Defense, undisclosed requests can disrupt new client requests.  Note: Software versions which have reached…