imPC@ndo IT

F5 vulnerabilities

1037 CVE

CVE-2025-59478
High 7.5

When a BIG-IP AFM denial-of-service (DoS) protection profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) process to terminate.  Note: Software versions which have reached End of Technical Support (…

f5 big-ip_advanced_firewall_manager
0.00EPSS
CVE-2024-23979
High 7.5

When SSL Client Certificate LDAP or Certificate Revocation List Distribution Point (CRLDP) authentication profile is configured on a virtual server, undisclosed requests can cause an increase in CPU resource utilization. Note: Software versions which ha…

f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · f5 big-ip_analytics · f5 big-ip_application_acceleration_manager · and 8 more
0.00EPSS
CVE-2022-1389
Low 3.1

On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP (fixed in 17.0.0), a cross-site request forgery (CSRF) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility. This vulnerability allows an attacker to …

f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · f5 big-ip_analytics · f5 big-ip_application_acceleration_manager · and 7 more
0.00EPSS
CVE-2023-38423
Medium 5.4

A cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user.  Note: Software versions which have reached End of Technical…

f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · f5 big-ip_advanced_web_application_firewall · f5 big-ip_analytics · and 15 more
0.00EPSS
CVE-2020-5866
Medium 5.5

In versions of NGINX Controller prior to 3.3.0, the helper.sh script, which is used optionally in NGINX Controller to change settings, uses sensitive items as command-line arguments.

f5 nginx_controller
0.00EPSS
CVE-2015-7393
High 7.4

dcoep in BIG-IP LTM, Analytics, APM, ASM, and Link Controller 11.2.0 through 11.6.0 and 12.0.0 before 12.0.0 HF1, BIG-IP AAM 11.4.0 through 11.6.0 and 12.0.0 before 12.0.0 HF1, BIG-IP AFM and PEM 11.3.0 through 11.6.0 and 12.0.0 before 12.0.0 HF1, BIG-IP DNS 1…

f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · f5 big-ip_analytics · f5 big-ip_application_acceleration_manager · and 16 more
0.00EPSS
CVE-2026-1642
Medium 5.9

A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers. An attacker with a man-in-the-middle (MITM) position on the upstream server side—along with conditions beyond the attacker's control…

f5 nginx_gateway_fabric · f5 nginx_ingress_controller · f5 nginx_instance_manager · f5 nginx_open_source · and 1 more
0.00EPSS
CVE-2024-10318
Medium 5.4

A session fixation issue was discovered in the NGINX OpenID Connect reference implementation, where a nonce was not checked at login time. This flaw allows an attacker to fix a victim's session to an attacker-controlled account. As a result, although the attac…

f5 nginx_api_connectivity_manager · f5 nginx_ingress_controller · f5 nginx_instance_manager · f5 nginx_openid_connect
0.00EPSS
CVE-2021-23002
Medium 4.5

When using BIG-IP APM 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, or all 12.1.x and 11.6.x versions or Edge Client versions 7.2.1.x before 7.2.1.1, 7.1.9.x before 7.1.9.8, or 7.1.8.x before 7.1.8.5, the session…

f5 access_policy_manager_clients · f5 big-ip_access_policy_manager
0.00EPSS
CVE-2025-52585
High 7.5

When a BIG-IP LTM Client SSL profile is configured on a virtual server with SSL Forward Proxy enabled and Anonymous Diffie-Hellman (ADH) ciphers enabled, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software …

f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · f5 big-ip_advanced_web_application_firewall · f5 big-ip_analytics · and 17 more
0.00EPSS
CVE-2025-46405
High 7.5

When Network Access is configured on a BIG-IP APM virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

f5 big-ip_access_policy_manager
0.00EPSS
CVE-2016-6249
Medium 5.3

F5 BIG-IP 12.0.0 and 11.5.0 - 11.6.1 REST requests which timeout during user account authentication may log sensitive attributes such as passwords in plaintext to /var/log/restjavad.0.log. It may allow local users to obtain sensitive information by reading the…

f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · f5 big-ip_analytics · f5 big-ip_application_acceleration_manager · and 7 more
0.00EPSS
CVE-2020-5908
Medium 5.5

In versions bundled with BIG-IP APM 12.1.0-12.1.5 and 11.6.1-11.6.5.2, Edge Client for Linux exposes full session ID in the local log files.

f5 big-ip_access_policy_manager
0.00EPSS
CVE-2020-5851
Medium 4.6

On impacted versions and platforms the Trusted Platform Module (TPM) system integrity check cannot detect modifications to specific system components. This issue only impacts specific engineering hotfixes and platforms. NOTE: This vulnerability does not affect…

f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · f5 big-ip_analytics · f5 big-ip_application_acceleration_manager · and 9 more
0.00EPSS
CVE-2019-11109
Medium 4.4

Logic issue in the subsystem for Intel(R) SPS before versions SPS_E5_04.01.04.275.0, SPS_SoC-X_04.00.04.100.0 and SPS_SoC-A_04.00.04.191.0 may allow a privileged user to potentially enable denial of service via local access.

f5 big-ip_10000s_firmware · f5 big-ip_10050s_firmware · f5 big-ip_10150v-n_firmware · f5 big-ip_10200v-s_firmware · and 30 more
0.00EPSS
CVE-2020-5855
Medium 4.3

When the Windows Logon Integration feature is configured for all versions of BIG-IP Edge Client for Windows, unauthorized users who have physical access to an authorized user's machine can get shell access under unprivileged user.

f5 big-ip_access_policy_manager · f5 big-ip_access_policy_manager_client
0.00EPSS
CVE-2025-61935
High 7.5

When a BIG IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

f5 big-ip_advanced_web_application_firewall · f5 big-ip_application_security_manager
0.00EPSS
CVE-2025-54479
High 7.5

When a classification profile is configured on a virtual server without an HTTP or HTTP/2 profile, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) …

f5 big-ip_next_cloud-native_network_functions · f5 big-ip_next_for_kubernetes · f5 big-ip_policy_enforcement_manager
0.00EPSS
CVE-2025-53856
High 7.5

When a virtual server, network address translation (NAT) object, or secure network address translation (SNAT) object uses the embedded Packet Velocity Acceleration (ePVA) feature, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to termin…

f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · f5 big-ip_advanced_web_application_firewall · f5 big-ip_analytics · and 17 more
0.00EPSS
CVE-2025-53474
High 7.5

When an iRule using an ILX::call command is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · f5 big-ip_advanced_web_application_firewall · f5 big-ip_analytics · and 17 more
0.00EPSS
CVE-2025-41430
High 7.5

When BIG-IP SSL Orchestrator is enabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

f5 big-ip_ssl_orchestrator
0.00EPSS
CVE-2022-27495
Medium 6.5

On all versions 1.3.x (fixed in 1.4.0) NGINX Service Mesh control plane endpoints are exposed to the cluster overlay network. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

f5 nginx_service_mesh
0.00EPSS
CVE-2026-40629
High 7.5

When SSL profiles are configured on a virtual server, undisclosed traffic can cause the virtual server to stop processing new client connections.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · f5 big-ip_advanced_web_application_firewall · f5 big-ip_analytics · and 20 more
0.00EPSS
CVE-2026-40618
High 7.5

When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel QuickAssist Technology (QAT) or on BIG-IP hardware platforms with the database variable crypto.hwacceleration set to disabled, undisclosed traffic can cause the …

f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · f5 big-ip_advanced_web_application_firewall · f5 big-ip_analytics · and 20 more
0.00EPSS
CVE-2026-40067
High 7.5

When a BIG-IP APM access policy is configured on a virtual server, undisclosed traffic can cause the apmd process to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

f5 big-ip_access_policy_manager
0.00EPSS