Skip to main content

Vendor archive

f5 CVEs

Beta · best-effort

1,024 CVEs tagged to vendor f575 Critical, 562 High, 372 Medium, 15 Low, 0 Unrated.

CVE-2017-6152

Published Mar 8, 2018

A local user on F5 BIG-IQ Centralized Management 5.1.0-5.2.0 with the Access Manager role has privileges to change the passwords of other users on the system, including the local…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6154

Published Mar 1, 2018

On F5 BIG-IP systems running 13.0.0, 12.1.0 - 12.1.3.1, or 11.6.1 - 11.6.2, the BIG-IP ASM bd daemon may core dump memory under some circumstances when processing undisclosed type…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-6150

Published Mar 1, 2018

Under certain conditions for F5 BIG-IP systems 13.0.0 or 12.1.0 - 12.1.3.1, using FastL4 profiles, when the Reassemble IP Fragments option is disabled (default), some specific lar…

CVSS 7.5 · High

CVE-2017-6169

Published Feb 6, 2018

In versions 13.0.0, 12.0.0-12.1.3, or 11.6.0-11.6.2, an F5 BIG-IP virtual server using the URL categorization feature may cause the Traffic Management Microkernel (TMM) to produce…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6142

Published Jan 19, 2018

X509 certificate verification was not correctly implemented in the early access "user id" feature in the F5 BIG-IP Advanced Firewall Manager versions 13.0.0, 12.1.0-12.1.2, and 11…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6167

Published Dec 21, 2017

In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM and WebSafe software version 13.0.0 and 12.1.0 - 12.1.2, race conditions in iControl REST may lead to co…

CVSS 7.5 · High

CVE-2017-6139

Published Dec 21, 2017

In F5 BIG-IP APM software version 13.0.0 and 12.1.2, under rare conditions, the BIG-IP APM system appends log details when responding to client requests. Details in the log file c…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6138

Published Dec 21, 2017

In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and WebSafe software version 13.0.0 and 12.1.0 - 12.1.2, malicious requests made to virtual servers…

CVSS 7.5 · High

CVE-2017-6136

Published Dec 21, 2017

In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and WebSafe software version 13.0.0 and 12.0.0 - 12.1.2, undisclosed traffic patterns sent to BIG-I…

CVSS 5.9 · Medium

CVE-2017-6135

Published Dec 21, 2017

In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and WebSafe software version 13.0.0, a slow memory leak as a result of undisclosed IPv4 or IPv6 pac…

CVSS 7.5 · High

CVE-2017-6134

Published Dec 21, 2017

In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and WebSafe software version 13.0.0, 12.1.0 - 12.1.2 and 11.5.1 - 11.6.1, an undisclosed sequence o…

CVSS 6.5 · Medium

CVE-2017-6133

Published Dec 21, 2017

In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM and WebSafe software version 13.0.0 and 12.1.0 - 12.1.2, undisclosed HTTP requests may cause a denial of…

CVSS 7.5 · High

CVE-2017-6132

Published Dec 21, 2017

In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and Websafe software version 13.0.0, 12.0.0 to 12.1.2, 11.6.0 to 11.6.1 and 11.5.0 - 11.5.4, an und…

CVSS 7.5 · High

CVE-2017-6129

Published Dec 21, 2017

In F5 BIG-IP APM software version 13.0.0 and 12.1.2, in some circumstances, APM tunneled VPN flows can cause a VPN/PPP connflow to be prematurely freed or cause TMM to stop respon…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-0304

Published Dec 21, 2017

A SQL injection vulnerability exists in the BIG-IP AFM management UI on versions 12.0.0, 12.1.0, 12.1.1, 12.1.2 and 13.0.0 that may allow a copy of the firewall rules to be tamper…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-0301

Published Dec 21, 2017

In F5 BIG-IP APM software versions 11.5.0, 11.5.1, 11.5.2, 11.5.3, 11.5.4, 11.6.0, 11.6.1, 12.0.0, 12.1.0, 12.1.1 and 12.1.2 BIG-IP APM portal access requests do not return the in…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort
Showing 851-875 of 1,024 CVEsPage 35 of 41