Loading HuntDB...

big-ip

133 Versions 150 CVEs

Versions

17.1.0, 16.1.0, 15.1.0

OTHER 1 CVE

16.1.4

SEMANTIC 2 CVEs

17..1

OTHER 1 CVE

15.1.10

SEMANTIC 2 CVEs

13.1.0

SEMANTIC 50 CVEs

classification-update-16.1.0-20230105_0508.im

OTHER 1 CVE

14.1.0-14.1.0.5

OTHER 2 CVEs

17.x

OTHER 1 CVE

classification-update-15.1.0-20221212_0929.im

OTHER 1 CVE

14.1.0.2-14.1.2.2

OTHER 1 CVE

15.0.0-15.0.1.1

OTHER 6 CVEs

Hotfix-BIGIP-12.1.4.1.0.97.6-ENG

OTHER 1 CVE

classification-update-16.1.0-20230216_0811.im

OTHER 1 CVE

15.1.0

SEMANTIC 60 CVEs

11.6.5

SEMANTIC 1 CVE

11.6.1-11.6.3.4

OTHER 2 CVEs

BIG-IP 11.5.1-11.6.4

OTHER 1 CVE

14.1.0

SEMANTIC 36 CVEs

classification_updates_15.1.0-20230302_1513.im

OTHER 1 CVE

classification-update-16.1.0-20230203_1610.im

OTHER 1 CVE

classification_updates_16.1.0-20230302_1513.im

OTHER 1 CVE

BIG-IQ 7.0.0

OTHER 1 CVE

Hotfix-BIGIP-11.5.4.2.74.291-HF2

OTHER 1 CVE

13.1.0-13.1.3.1

OTHER 11 CVEs

classification-update-16.1.0-20221110_0614.im

OTHER 1 CVE

16.1.2.2

OTHER 3 CVEs

17.0.0

SEMANTIC 57 CVEs

14.0.0-14.1.2.3

OTHER 1 CVE

Hotfix-BIGIP-15.1.10.2.0.44.2-ENG.iso

OTHER 2 CVEs

13.1.x

OTHER 31 CVEs

11.5.9-11.5.10

OTHER 1 CVE

classification-update-16.1.0-20220919_0728.im

OTHER 1 CVE

13.1.0-13.1.1.4

OTHER 1 CVE

classification-update-17.0.0-20221222_0627.im

OTHER 1 CVE

14.0.0-14.0.0.5

OTHER 2 CVEs

classification-update-15.1.0-20220929_1149.im

OTHER 1 CVE

classification-update-15.1.0-20220919_0728.im

OTHER 1 CVE

14.0.0-14.1.2

OTHER 1 CVE

11.6.x

OTHER 26 CVEs

12.1.0-12.1.4.2

OTHER 1 CVE

13.0.0-13.1.1.4

OTHER 10 CVEs

BIG-IP 14.1.0-14.1.0.5

OTHER 12 CVEs

16.1.x

OTHER 42 CVEs

classification-update-16.1.0-20221027_0652.im

OTHER 1 CVE

12.1.4.1-12.1.5

OTHER 1 CVE

BIG-IP 15.0.0-15.0.1.1

OTHER 1 CVE

classification-update-17.0.0-20221125_0422.im

OTHER 1 CVE

14.0.0-14.1.2.2

OTHER 2 CVEs

classification-update-17.0.0-20220929_1149.im

OTHER 1 CVE

12.1.0-12.1.5

OTHER 10 CVEs

12.1.x

OTHER 27 CVEs

15.1.5.1

OTHER 2 CVEs

11.5.1-11.6.5.1

OTHER 1 CVE

13.1.5

SEMANTIC 1 CVE

classification-update-17.0.0-20230203_1610.im

OTHER 1 CVE

classification-update-17.0.0-20221212_0929.im

OTHER 1 CVE

12.1.0-12.1.4

OTHER 7 CVEs

5.1.0-5.4.0

OTHER 2 CVEs

14.1.x

OTHER 45 CVEs

14.1.0-14.1.2.2

OTHER 5 CVEs

14.1.5

SEMANTIC 2 CVEs

classification-update-17.0.0-20221014_1320.im

OTHER 1 CVE

11.5.1-11.5.8

OTHER 2 CVEs

classification-update-17.0.0-20230105_0508.im

OTHER 1 CVE

16.1.2

SEMANTIC 1 CVE

12.1.6

SEMANTIC 1 CVE

iWorkflow 2.3.0

OTHER 2 CVEs

15.0.0-15.0.1

OTHER 10 CVEs

classification-update-16.1.0-20221222_0627.im

OTHER 1 CVE

16.0.x

OTHER 1 CVE

classification-update-15.1.0-20230203_1610.im

OTHER 1 CVE

Engineering Hotfix Available

OTHER 1 CVE

15.1.5

SEMANTIC 1 CVE

11.5.2-11.6.4

OTHER 1 CVE

classification-update-15.1.0-20221110_0614.im

OTHER 1 CVE

5.0.0-5.4.0

OTHER 1 CVE

Hotfix-BIGIP-16.1.4.1.0.50.5-ENG.iso

OTHER 2 CVEs

16.0.0

SEMANTIC 2 CVEs

13.0.0-13.1.1.5

OTHER 1 CVE

classification-update-15.1.0-20221125_0422.im

OTHER 1 CVE

Hotfix-BIGIP-14.1.5.6.0.10.6-ENG.iso

OTHER 2 CVEs

classification-update-15.1.0-20230216_0811.im

OTHER 1 CVE

classification-update-15.1.0-20221014_1320.im

OTHER 1 CVE

14.0.0-14.0.0.4

OTHER 11 CVEs

11.5.1-11.6.5

OTHER 2 CVEs

BIG-IP 12.1.0-12.1.4.1

OTHER 1 CVE

14.0.0-14.0.1

OTHER 10 CVEs

classification-update-17.0.0-20221110_0614.im

OTHER 1 CVE

14.1.0-14.1.2

OTHER 6 CVEs

15.1.4.1

OTHER 1 CVE

15.1.4

SEMANTIC 1 CVE

Hotfix-BIGIP-14.1.2.1.0.83.4-ENG

OTHER 1 CVE

15.1.x

OTHER 47 CVEs

11.5.2-11.6.5

OTHER 2 CVEs

Hotfix-BIGIP-17.1.0.3.0.75.4-ENG.iso

OTHER 2 CVEs

14.0.0-14.1.0.5

OTHER 1 CVE

11.6.0-11.6.5.1

OTHER 1 CVE

classification-update-17.0.0-20220919_0728.im

OTHER 1 CVE

classification-update-17.0.0-20230216_0811.im

OTHER 1 CVE

6.0

MAJOR_MINOR 1 CVE

classification-update-17.0.0-20221027_0652.im

OTHER 1 CVE

16.1.2.1

OTHER 1 CVE

13.1.0-13.1.3.2

OTHER 2 CVEs

11.5.2-11.6.5.1

OTHER 3 CVEs

14.1.4.6

OTHER 2 CVEs

6.0.0-6.1.0

OTHER 1 CVE

11.5.1-11.6.4

OTHER 4 CVEs

17.1.0

SEMANTIC 48 CVEs

13.1.1.5-13.1.3.1

OTHER 1 CVE

classification-update-16.1.0-20230120_1249.im

OTHER 1 CVE

13.1.0-13.1.1.5

OTHER 1 CVE

classification_updates_17.0.0-20230302_1513.im

OTHER 1 CVE

17.0.x

OTHER 11 CVEs

classification-update-16.1.0-20221212_0929.im

OTHER 1 CVE

14.0.0.5-14.0.1

OTHER 1 CVE

classification-update-15.1.0-20221027_0652.im

OTHER 1 CVE

14.0.0

SEMANTIC 1 CVE

16.1.0

SEMANTIC 66 CVEs

BIG-IQ 6.0.0-6.1.0

OTHER 2 CVEs

11.6.4-11.6.5

OTHER 1 CVE

classification-update-16.1.0-20221014_1320.im

OTHER 1 CVE

classification-update-17.0.0-20230120_1249.im

OTHER 1 CVE

classification-update-15.1.0-20230105_0508.im

OTHER 1 CVE

Enterprise Manager 3.1.1

OTHER 2 CVEs

BIG-IP 15.0.0

OTHER 1 CVE

12.1.0-12.1.4.1

OTHER 4 CVEs

classification-update-15.1.0-20230120_1249.im

OTHER 1 CVE

classification-update-16.1.0-20220929_1149.im

OTHER 1 CVE

classification-update-16.1.0-20221125_0422.im

OTHER 1 CVE

Hotfix-BIGIP-17.1.1.0.2.6-ENG.iso

OTHER 2 CVEs

BIG-IP 15.0.0-15.1.0

OTHER 1 CVE

classification-update-15.1.0-20221222_0627.im

OTHER 1 CVE

Hotfix-BIGIP-13.1.5.1.0.20.2-ENG.iso

OTHER 2 CVEs

Recent CVEs

CVE-2024-31156

A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

HIGH May 08, 2024

CVE-2024-33604

A reflected cross-site scripting (XSS) vulnerability exist in undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

MEDIUM May 08, 2024

CVE-2024-27202

A DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

MEDIUM May 08, 2024

CVE-2024-24775

When a virtual server is enabled with VLAN group and SNAT listener is configured, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

HIGH Feb 14, 2024

CVE-2023-41373

A directory traversal vulnerability exists in the BIG-IP Configuration Utility that may allow an authenticated attacker to execute commands on the BIG-IP system. For BIG-IP system running in Appliance mode, a successful exploit can allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

HIGH Oct 10, 2023

CVE-2023-40542

When TCP Verified Accept is enabled on a TCP profile that is configured on a Virtual Server, undisclosed requests can cause an increase in memory resource utilization.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

HIGH Oct 10, 2023

CVE-2023-22839

On BIG-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all version of 13.1.x, when a DNS profile with the Rapid Response Mode setting enabled is configured on a virtual server with hardware SYN cookies enabled, undisclosed requests cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

HIGH Feb 01, 2023

CVE-2023-22326

In BIG-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all versions of 13.1.x, and all versions of BIG-IQ 8.x and 7.1.x, incorrect permission assignment vulnerabilities exist in the iControl REST and TMOS shell (tmsh) dig command which may allow an authenticated attacker with resource administrator or administrator role privileges to view sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

MEDIUM Feb 01, 2023

CVE-2023-22323

In BIP-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when OCSP authentication profile is configured on a virtual server, undisclosed requests can cause an increase in CPU resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

HIGH Feb 01, 2023

CVE-2022-41833

In all BIG-IP 13.1.x versions, when an iRule containing the HTTP::collect command is configured on a virtual server, undisclosed requests can cause Traffic Management Microkernel (TMM) to terminate.

HIGH Oct 19, 2022