EN
58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

Vulnerabilità F5

1039 CVE

Vulnerabilità F5
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2024-28883 HIGH 7.4 f5 big-ip_access_policy_manager An origin validation vulnerability exists in BIG-IP APM browser network access VPN client for Windows, macOS and Linux which may allow an attacker to bypass F5 endpoint inspection. Note: Software versions which have reached End of Technical Support ( 0,2% —
CVE-2024-24966 MED 6.2 f5 f5os-a When LDAP remote authentication is configured on F5OS, a remote user without an assigned role will be incorrectly authorized.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. 0,2% —
CVE-2025-61933 MED 6.1 f5 big-ip_access_policy_manager A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of BIG-IP APM that allows an attacker to run JavaScript in the context of the targeted logged-out user.  Note: Software versions which have reached End of Technical Support (EoT 0,2% —
CVE-2023-22283 MED 6.5 f5 big-ip_access_policy_manager On versions beginning in 7.1.5 to before 7.2.3.1, a DLL hijacking vulnerability exists in the BIG-IP Edge Client for Windows. User interaction and administrative privileges are required to exploit this vulnerability because the victim user needs to run the exe 0,2% —
CVE-2026-22548 MED 5.9 f5 big-ip_advanced_web_application_firewall When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests along with conditions beyond the attacker's control can cause the bd process to terminate.  Note: Software versions which have reached End of Technical Su 0,2% —
CVE-2022-33962 MED 6.7 f5 big-ip_access_policy_manager In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, certain iRules commands may allow an attacker to bypass the access control restrictions for a self IP address, regard 0,2% —
CVE-2023-36494 MED 4.4 f5 f5os-a Audit logs on F5OS-A may contain undisclosed sensitive information.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. 0,2% —
CVE-2020-5899 HIGH 7.8 f5 nginx_controller In NGINX Controller 3.0.0-3.4.0, recovery code required to change a user's password is transmitted and stored in the database in plain text, which allows an attacker who can intercept the database connection or have read access to the database, to request a pa 0,2% —
CVE-2020-5928 LOW 3.1 f5 big-ip_application_security_manager In versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.6, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, BIG-IP ASM Configuration utility CSRF protection token can be reused multiple times. 0,2% —
CVE-2025-60013 MED 4.6 f5 f5os-a When a highly-privileged, authenticated attacker attempts to initialize the rSeries FIPS module using a password with special shell metacharacters, arbitrary system commands may be executed, and the FIPS hardware security module (HSM) may fail to initialize. A 0,2% —
CVE-2024-21782 MED 6.7 f5 big-ip_access_policy_manager BIG-IP or BIG-IQ Resource Administrators and Certificate Managers who have access to the secure copy (scp) utility but do not have access to Advanced shell (bash) can execute arbitrary commands with a specially crafted command string. This vulnerability is due 0,2% —
CVE-2023-3470 MED 6.0 f5 big-ip_10200v-f_firmware Specific F5 BIG-IP platforms with Cavium Nitrox FIPS HSM cards generate a deterministic password for the Crypto User account.  The predictable nature of the password allows an authenticated user with TMSH access to the BIG-IP system, or anyone with physical a 0,2% —
CVE-2023-45219 MED 4.4 f5 big-ip_access_policy_manager Exposure of Sensitive Information vulnerability exist in an undisclosed BIG-IP TMOS shell (tmsh) command which may allow an authenticated attacker with resource administrator role privileges to view sensitive information.   Note: Software versions which have 0,2% —
CVE-2023-39447 MED 4.4 f5 big-ip_access_policy_manager When BIG-IP APM Guided Configurations are configured, undisclosed sensitive information may be logged in restnoded log.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. 0,2% —
CVE-2023-43124 MED 5.3 f5 big-ip_access_policy_manager BIG-IP APM clients may send IP traffic outside of the VPN tunnel.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated 0,2% —
CVE-2023-43485 MED 5.5 f5 big-ip_access_policy_manager When TACACS+ audit forwarding is configured on BIG-IP or BIG-IQ system, sharedsecret is logged in plaintext in the audit log.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. 0,2% —
CVE-2023-41253 MED 5.5 f5 big-ip_domain_name_system When on BIG-IP DNS or BIG-IP LTM enabled with DNS Services License, and a TSIG key is created, it is logged in plaintext in the audit log.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. 0,2% —
CVE-2023-28724 HIGH 7.1 f5 nginx_api_connectivity_manager NGINX Management Suite default file permissions are set such that an authenticated attacker may be able to modify sensitive files on NGINX Instance Manager and NGINX API Connectivity Manager.   Note: Software versions which have reached End of Technical Suppo 0,2% —
CVE-2024-23976 MED 6.0 f5 big-ip_access_policy_manager When running in Appliance mode, an authenticated attacker assigned the Administrator role may be able to bypass Appliance mode restrictions utilizing iAppsLX templates on a BIG-IP system.  Note: Software versions which have reached End of Technical Support (Eo 0,2% —
CVE-2024-28132 MED 4.4 f5 big-ip_next_cloud-native_network_functions Exposure of Sensitive Information vulnerability exists in the GSLB container, which may allow an authenticated attacker with local access to view sensitive information.  Note: Software versions which have reached End of Technical Support (EoTS) are not evalua 0,2% —
CVE-2025-43878 MED 6.0 f5 f5os-a When running in Appliance mode, an authenticated attacker assigned the Administrator or Resource Administrator role may be able to bypass Appliance mode restrictions utilizing system diagnostics tcpdump command utility on a F5OS-C/A system.  Note: Software 0,2% —
CVE-2026-20732 LOW 3.1 f5 big-ip_access_policy_manager A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. 0,2% —
CVE-2025-23413 MED 4.4 f5 big-ip_next_central_manager When users log in through the webUI or API using local authentication, BIG-IP Next Central Manager may log sensitive information in the pgaudit log files. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. 0,2% —
CVE-2026-41217 HIGH 7.9 f5 big-ip_access_policy_manager A vulnerability exists in an undisclosed BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with resource administrator or administrator role to execute arbitrary system commands with higher privileges. In Appliance mode deployments, a s 0,2% —
CVE-2026-28755 MED 5.4 f5 nginx_open_source NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when configured with the ssl_verify_client on and ssl_ocsp on directives, allowing the TLS handshake to succeed even 0,2% —