<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – BIG-IP (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/big-ip.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/big-ip-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – BIG-IP (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:48 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-42930 – When running in Appliance mode, an authenticated attacker assigned the 'Administ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42930</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42930</guid>
    <pubDate>Wed, 13 May 2026 16:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42930</strong></p>
  <p>When running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may be able to bypass Appliance mode restrictions on a BIG-IP system.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-35</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42930">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42406 – A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42406</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42406</guid>
    <pubDate>Wed, 13 May 2026 16:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42406</strong></p>
  <p>A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands.     Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-267</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42406">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41957 – An authenticated remote code execution vulnerability through undisclosed vectors...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41957</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41957</guid>
    <pubDate>Wed, 13 May 2026 16:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41957</strong></p>
  <p>An authenticated remote code execution vulnerability through undisclosed vectors exists in the BIG-IP and BIG-IQ Configuration utility.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41957">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41953 – A vulnerability exists in BIG-IP systems where a highly privileged, authenticate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41953</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41953</guid>
    <pubDate>Wed, 13 May 2026 16:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41953</strong></p>
  <p>A vulnerability exists in BIG-IP systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can modify configuration objects resulting in privilege escalation.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41953">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41218 – When BIG-IP PEM iRules are configured on a virtual server (iRules using commands...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41218</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41218</guid>
    <pubDate>Wed, 13 May 2026 16:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41218</strong></p>
  <p>When BIG-IP PEM iRules are configured on a virtual server (iRules using commands starting with CLASSIFICATION::, CLASSIFY::, PEM::, PSC::, and the urlcatquery command), undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41218">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41217 – A vulnerability exists in an undisclosed BIG-IP TMOS Shell (tmsh) command that m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41217</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41217</guid>
    <pubDate>Wed, 13 May 2026 16:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41217</strong></p>
  <p>A vulnerability exists in an undisclosed BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with resource administrator or administrator role to execute arbitrary system commands with higher privileges. In Appliance mode deployments, a successful exploit can allow the attacker to cross a security boundary.   Note: Software versions which have reached End of Technical Suppor…</p>
  <p><strong>CVSS:</strong> 7.9 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41217">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40698 – A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40698</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40698</guid>
    <pubDate>Wed, 13 May 2026 16:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40698</strong></p>
  <p>A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can create SNMP configuration objects through iControl REST or the TMOS shell (tmsh) resulting in privilege escalation.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40698">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40618 – When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40618</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40618</guid>
    <pubDate>Wed, 13 May 2026 16:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40618</strong></p>
  <p>When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel QuickAssist Technology (QAT) or on BIG-IP hardware platforms with the database variable crypto.hwacceleration set to disabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.    Note: Software versions which have reached End of Technical Support (EoTS) are not ev…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-131</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40618">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40067 – When a BIG-IP APM access policy is configured on a virtual server, undisclosed t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40067</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40067</guid>
    <pubDate>Wed, 13 May 2026 16:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40067</strong></p>
  <p>When a BIG-IP APM access policy is configured on a virtual server, undisclosed traffic can cause the apmd process to terminate.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40067">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40061 – When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iContro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40061</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40061</guid>
    <pubDate>Wed, 13 May 2026 16:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40061</strong></p>
  <p>When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system commands with higher privileges. In Appliance mode deployments, a successful exploit can allow the attacker to cross a security boundary.  Note: Softwar…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40061">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40060 – When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual ser...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40060</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40060</guid>
    <pubDate>Wed, 13 May 2026 16:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40060</strong></p>
  <p>When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate.       Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-252</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40060">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39458 – When a BIG-IP DNS profile enabled with DNS cache is configured on a virtual serv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39458</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39458</guid>
    <pubDate>Wed, 13 May 2026 16:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39458</strong></p>
  <p>When a BIG-IP DNS profile enabled with DNS cache is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-824</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39458">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39455 – When the BIG-IP Configuration utility is configured to use Lightweight Directory...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39455</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39455</guid>
    <pubDate>Wed, 13 May 2026 16:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39455</strong></p>
  <p>When the BIG-IP Configuration utility is configured to use Lightweight Directory Access Protocol (LDAP) authentication, undisclosed traffic can cause the httpd process to exhaust the available file descriptors.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-772</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39455">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32673 – A vulnerability exists in BIG-IP scripted monitors that may allow an authenticat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32673</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32673</guid>
    <pubDate>Wed, 13 May 2026 16:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32673</strong></p>
  <p>A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system commands with higher privileges. In appliance mode deployments, a successful exploit can allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not eva…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32673">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32643 – A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32643</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32643</guid>
    <pubDate>Wed, 13 May 2026 16:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32643</strong></p>
  <p>A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32643">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2507 – When BIG-IP AFM or BIG-IP DDoS is provisioned, undisclosed traffic can cause TMM...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2507</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2507</guid>
    <pubDate>Wed, 18 Feb 2026 17:21:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2507</strong></p>
  <p>When BIG-IP AFM or BIG-IP DDoS is provisioned, undisclosed traffic can cause TMM to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2507">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61935 – When a BIG IP Advanced WAF or ASM security policy is configured on a virtual ser...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61935</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61935</guid>
    <pubDate>Wed, 15 Oct 2025 16:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61935</strong></p>
  <p>When a BIG IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-252</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61935">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-58071 – When IPsec is configured on the BIG-IP system, undisclosed traffic can cause the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58071</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58071</guid>
    <pubDate>Wed, 15 Oct 2025 16:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-58071</strong></p>
  <p>When IPsec is configured on the BIG-IP system, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-457</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58071">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61960 – When a per-request policy is configured on a BIG-IP APM portal access virtual se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61960</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61960</guid>
    <pubDate>Wed, 15 Oct 2025 14:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61960</strong></p>
  <p>When a per-request policy is configured on a BIG-IP APM portal access virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61960">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61958 – A vulnerability exists in the iHealth command that may allow an authenticated at...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61958</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61958</guid>
    <pubDate>Wed, 15 Oct 2025 14:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61958</strong></p>
  <p>A vulnerability exists in the iHealth command that may allow an authenticated attacker with at least a resource administrator role to bypass tmsh restrictions and gain access to a bash shell.  For BIG-IP systems running in Appliance mode, a successful exploit can allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not ev…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61958">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61938 – When a BIG-IP Advanced WAF or ASM security policy is configured with a URL great...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61938</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61938</guid>
    <pubDate>Wed, 15 Oct 2025 14:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61938</strong></p>
  <p>When a BIG-IP Advanced WAF or ASM security policy is configured with a URL greater than 1024 characters in length for the Data Guard Protection Enforcement setting, either manually or through the automatic Policy Builder, the bd process can terminate repeatedly.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61938">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-59781 – When DNS cache is configured on a BIG-IP or BIG-IP Next CNF virtual server, undi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59781</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59781</guid>
    <pubDate>Wed, 15 Oct 2025 14:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-59781</strong></p>
  <p>When DNS cache is configured on a BIG-IP or BIG-IP Next CNF virtual server, undisclosed DNS queries can cause an increase in memory resource utilization.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-459</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59781">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-59481 – A vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tm...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59481</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59481</guid>
    <pubDate>Wed, 15 Oct 2025 14:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-59481</strong></p>
  <p>A vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with at least resource administrator role to execute arbitrary system commands with higher privileges.  A successful exploit can allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not eval…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59481">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-59478 – When a BIG-IP AFM denial-of-service (DoS) protection profile is configured on a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59478</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59478</guid>
    <pubDate>Wed, 15 Oct 2025 14:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-59478</strong></p>
  <p>When a BIG-IP AFM denial-of-service (DoS) protection profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) process to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-824</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59478">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-58096 – When the database variable tm.tcpudptxchecksum is configured as non-default valu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58096</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58096</guid>
    <pubDate>Wed, 15 Oct 2025 14:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-58096</strong></p>
  <p>When the database variable tm.tcpudptxchecksum is configured as non-default value Software-only on a BIG-IP system, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58096">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-55669 – When the BIG-IP Advanced WAF and ASM security policy and a server-side HTTP/2 pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55669</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55669</guid>
    <pubDate>Wed, 15 Oct 2025 14:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-55669</strong></p>
  <p>When the BIG-IP Advanced WAF and ASM security policy and a server-side HTTP/2 profile are configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-672</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55669">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-55036 – When BIG-IP SSL Orchestrator explicit forward proxy is configured on a virtual s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55036</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55036</guid>
    <pubDate>Wed, 15 Oct 2025 14:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-55036</strong></p>
  <p>When BIG-IP SSL Orchestrator explicit forward proxy is configured on a virtual server and the proxy connect feature is enabled, undisclosed traffic may cause memory corruption.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55036">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54858 – When a BIG-IP Advanced WAF or BIG-IP ASM Security Policy is configured with a JS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54858</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54858</guid>
    <pubDate>Wed, 15 Oct 2025 14:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54858</strong></p>
  <p>When a BIG-IP Advanced WAF or BIG-IP ASM Security Policy is configured with a JSON content profile that has a malformed JSON schema, and the security policy is applied to a virtual server, undisclosed requests can cause the bd process to terminate.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-674</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54858">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54854 – When a BIG-IP APM OAuth access profile (Resource Server or Resource Client) is c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54854</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54854</guid>
    <pubDate>Wed, 15 Oct 2025 14:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54854</strong></p>
  <p>When a BIG-IP APM OAuth access profile (Resource Server or Resource Client) is configured on a virtual server, undisclosed traffic can cause the apmd process to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54854">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-53856 – When a virtual server, network address translation (NAT) object, or secure netwo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53856</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53856</guid>
    <pubDate>Wed, 15 Oct 2025 14:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-53856</strong></p>
  <p>When a virtual server, network address translation (NAT) object, or secure network address translation (SNAT) object uses the embedded Packet Velocity Acceleration (ePVA) feature, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  To determine which BIG-IP platforms have an ePVA chip refer to  K12837: Overview of the ePVA feature https://my.f5.com/manage/s/artic…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-705</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53856">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-53521 – When a BIG-IP APM access policy is configured on a virtual server, specific mali...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53521</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53521</guid>
    <pubDate>Wed, 15 Oct 2025 14:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-53521</strong></p>
  <p>When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).    Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53521">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41430 – When BIG-IP SSL Orchestrator is enabled, undisclosed traffic can cause the Traff...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41430</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41430</guid>
    <pubDate>Wed, 15 Oct 2025 14:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41430</strong></p>
  <p>When BIG-IP SSL Orchestrator is enabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.    Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41430">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-52585 – When a BIG-IP LTM Client SSL profile is configured on a virtual server with SSL ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-52585</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-52585</guid>
    <pubDate>Wed, 13 Aug 2025 15:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-52585</strong></p>
  <p>When a BIG-IP LTM Client SSL profile is configured on a virtual server with SSL Forward Proxy enabled and Anonymous Diffie-Hellman (ADH) ciphers enabled, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate.      Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-52585">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-46405 – When Network Access is configured on a BIG-IP APM virtual server, undisclosed tr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46405</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46405</guid>
    <pubDate>Wed, 13 Aug 2025 15:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-46405</strong></p>
  <p>When Network Access is configured on a BIG-IP APM virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.      Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46405">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41431 – When connection mirroring is configured on a virtual server, undisclosed request...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41431</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41431</guid>
    <pubDate>Wed, 07 May 2025 22:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41431</strong></p>
  <p>When connection mirroring is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate in the standby BIG-IP systems in a traffic group.    Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41431">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-36525 – When a BIG-IP APM virtual server is configured to use a PingAccess profile, undi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36525</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36525</guid>
    <pubDate>Wed, 07 May 2025 22:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-36525</strong></p>
  <p>When a BIG-IP APM virtual server is configured to use a PingAccess profile, undisclosed requests can cause TMM to terminate.    Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36525">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-36504 – When a BIG-IP HTTP/2 httprouter profile is configured on a virtual server, undis...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36504</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36504</guid>
    <pubDate>Wed, 07 May 2025 22:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-36504</strong></p>
  <p>When a BIG-IP HTTP/2 httprouter profile is configured on a virtual server, undisclosed responses can cause an increase in memory resource utilization.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36504">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-35995 – When a BIG-IP PEM system is licensed with URL categorization, and the URL catego...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-35995</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-35995</guid>
    <pubDate>Wed, 07 May 2025 22:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-35995</strong></p>
  <p>When a BIG-IP PEM system is licensed with URL categorization, and the URL categorization policy or an iRule with the urlcat command is enabled on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-35995">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-31644 – When running in Appliance mode, a command injection vulnerability exists in an u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-31644</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-31644</guid>
    <pubDate>Wed, 07 May 2025 22:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-31644</strong></p>
  <p>When running in Appliance mode, a command injection vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command which may allow an authenticated attacker with administrator role privileges to execute arbitrary system commands. A successful exploit can allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31644">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-24326 – When BIG-IP Advanced WAF/ASM Behavioral DoS (BADoS) TLS Signatures feature is co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24326</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24326</guid>
    <pubDate>Wed, 05 Feb 2025 18:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-24326</strong></p>
  <p>When BIG-IP Advanced WAF/ASM Behavioral DoS (BADoS) TLS Signatures feature is configured, undisclosed traffic can case an increase in memory resource utilization.      Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24326">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-24320 – A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24320</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24320</guid>
    <pubDate>Wed, 05 Feb 2025 18:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-24320</strong></p>
  <p>A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. This vulnerability is due to an incomplete fix for  CVE-2024-31156 https://my.f5.com/manage/s/article/K000138636 .   Note: Software versions which have reached End of Technical Support (EoTS) a…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24320">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-24312 – When BIG-IP AFM is provisioned with IPS module enabled and protocol inspection p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24312</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24312</guid>
    <pubDate>Wed, 05 Feb 2025 18:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-24312</strong></p>
  <p>When BIG-IP AFM is provisioned with IPS module enabled and protocol inspection profile is configured on a virtual server or firewall rule or policy, undisclosed traffic can cause an increase in CPU resource utilization.    Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24312">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-23412 – When BIG-IP APM Access Profile is configured on a virtual server, undisclosed re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-23412</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-23412</guid>
    <pubDate>Wed, 05 Feb 2025 18:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-23412</strong></p>
  <p>When BIG-IP APM Access Profile is configured on a virtual server, undisclosed request can cause TMM to terminate.        Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23412">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-22891 – When BIG-IP PEM Control Plane listener Virtual Server is configured with Diamete...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22891</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22891</guid>
    <pubDate>Wed, 05 Feb 2025 18:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-22891</strong></p>
  <p>When BIG-IP PEM Control Plane listener Virtual Server is configured with Diameter Endpoint profile, undisclosed traffic can cause the Virtual Server to stop processing new client connections and an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-772</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22891">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-21091 – When SNMP v1 or v2c are disabled on the BIG-IP, undisclosed requests can cause a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-21091</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-21091</guid>
    <pubDate>Wed, 05 Feb 2025 18:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-21091</strong></p>
  <p>When SNMP v1 or v2c are disabled on the BIG-IP, undisclosed requests can cause an increase in memory resource utilization.      Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-21091">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20058 – When a BIG-IP message routing profile is configured on a virtual server, undiscl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20058</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20058</guid>
    <pubDate>Wed, 05 Feb 2025 18:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20058</strong></p>
  <p>When a BIG-IP message routing profile is configured on a virtual server, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20058">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20029 – Command injection vulnerability exists in iControl REST and BIG-IP TMOS Shell (t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20029</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20029</guid>
    <pubDate>Wed, 05 Feb 2025 18:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20029</strong></p>
  <p>Command injection vulnerability exists in iControl REST and BIG-IP TMOS Shell (tmsh) save command, which may allow an authenticated attacker to execute arbitrary system commands.      Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20029">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-45844 – BIG-IP monitor functionality may allow an attacker to bypass access control rest...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45844</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45844</guid>
    <pubDate>Wed, 16 Oct 2024 15:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-45844</strong></p>
  <p>BIG-IP monitor functionality may allow an attacker to bypass access control restrictions, regardless of the port lockdown settings.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45844">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-41727 – In BIG-IP tenants running on r2000 and r4000 series hardware, or BIG-IP Virtual ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-41727</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-41727</guid>
    <pubDate>Wed, 14 Aug 2024 15:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-41727</strong></p>
  <p>In BIG-IP tenants running on r2000 and r4000 series hardware, or BIG-IP Virtual Edition (VEs) using Intel E810 SR-IOV NIC, undisclosed traffic can cause an increase in memory resource utilization.    Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-41727">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-39778 – When a stateless virtual server is configured on BIG-IP system with a High-Speed...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39778</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39778</guid>
    <pubDate>Wed, 14 Aug 2024 15:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-39778</strong></p>
  <p>When a stateless virtual server is configured on BIG-IP system with a High-Speed Bridge (HSB), undisclosed requests can cause TMM to terminate.    Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-702</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39778">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-32049 – BIG-IP Next Central Manager (CM) may allow an unauthenticated, remote attacker t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-32049</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-32049</guid>
    <pubDate>Wed, 08 May 2024 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-32049</strong></p>
  <p>BIG-IP Next Central Manager (CM) may allow an unauthenticated, remote attacker to obtain the BIG-IP Next LTM/WAF instance credentials.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-300</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32049">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-31156 – A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-31156</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-31156</guid>
    <pubDate>Wed, 08 May 2024 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-31156</strong></p>
  <p>A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-31156">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-28883 – An origin validation vulnerability exists in 

BIG-IP APM browser network access...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-28883</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-28883</guid>
    <pubDate>Wed, 08 May 2024 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-28883</strong></p>
  <p>An origin validation vulnerability exists in   BIG-IP APM browser network access VPN client      for Windows, macOS and Linux which may allow an attacker to bypass F5 endpoint inspection.    Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-346</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-28883">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-26026 – An SQL injection vulnerability exists in the BIG-IP Next Central Manager API (UR...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-26026</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-26026</guid>
    <pubDate>Wed, 08 May 2024 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-26026</strong></p>
  <p>An SQL injection vulnerability exists in the BIG-IP Next Central Manager API (URI).  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-26026">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-25560 – When BIG-IP AFM is licensed and provisioned, undisclosed DNS traffic can cause t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-25560</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-25560</guid>
    <pubDate>Wed, 08 May 2024 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-25560</strong></p>
  <p>When BIG-IP AFM is licensed and provisioned, undisclosed DNS traffic can cause the Traffic Management Microkernel (TMM) to terminate.      Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-25560">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-21793 – An OData injection vulnerability exists in the BIG-IP Next Central Manager API (...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21793</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21793</guid>
    <pubDate>Wed, 08 May 2024 15:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-21793</strong></p>
  <p>An OData injection vulnerability exists in the BIG-IP Next Central Manager API (URI).  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21793">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23982 – When a BIG-IP PEM classification profile is configured on a UDP virtual server, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23982</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23982</guid>
    <pubDate>Wed, 14 Feb 2024 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23982</strong></p>
  <p>When a BIG-IP PEM classification profile is configured on a UDP virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. This issue affects classification engines using signatures released between 09-08-2022 and 02-16-2023. See the table in the F5 Security Advisory for a complete list of affected classification signature files.  NOTE: Software versions…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23982">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23805 – Undisclosed requests can cause the Traffic Management Microkernel (TMM) to termi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23805</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23805</guid>
    <pubDate>Wed, 14 Feb 2024 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23805</strong></p>
  <p>Undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. For the Application Visibility and Reporting module, this may occur when the HTTP Analytics profile with URLs enabled under Collected Entities is configured on a virtual server and the DB variables avr.IncludeServerInURI or avr.CollectOnlyHostnameFromURI are enabled. For BIG-IP Advanced WAF and ASM, this may occ…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-131</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23805">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23314 – When HTTP/2 is configured on BIG-IP or BIG-IP Next SPK systems, undisclosed resp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23314</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23314</guid>
    <pubDate>Wed, 14 Feb 2024 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23314</strong></p>
  <p>When HTTP/2 is configured on BIG-IP or BIG-IP Next SPK systems, undisclosed responses can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23314">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23308 – When a BIG-IP Advanced WAF or BIG-IP ASM policy with a Request Body Handling opt...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23308</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23308</guid>
    <pubDate>Wed, 14 Feb 2024 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23308</strong></p>
  <p>When a BIG-IP Advanced WAF or BIG-IP ASM policy with a Request Body Handling option is attached to a virtual server, undisclosed requests can cause the BD process to terminate. The condition results from setting the Request Body Handling option in the Header-Based Content Profile for an Allowed URL with "Apply value and content signatures and detect threat campaigns."  Note: Software versions whi…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23308">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23306 – A vulnerability exists in BIG-IP Next CNF and SPK systems that may allow access ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23306</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23306</guid>
    <pubDate>Wed, 14 Feb 2024 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23306</strong></p>
  <p>A vulnerability exists in BIG-IP Next CNF and SPK systems that may allow access to undisclosed sensitive files.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23306">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22389 – When BIG-IP is deployed in high availability (HA) and an iControl REST API token...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22389</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22389</guid>
    <pubDate>Wed, 14 Feb 2024 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22389</strong></p>
  <p>When BIG-IP is deployed in high availability (HA) and an iControl REST API token is updated, the change does not sync to the peer device.     Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22389">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-21789 – When a BIG-IP ASM/Advanced WAF security policy is configured on a virtual server...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21789</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21789</guid>
    <pubDate>Wed, 14 Feb 2024 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-21789</strong></p>
  <p>When a BIG-IP ASM/Advanced WAF security policy is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-772</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21789">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-21771 – For unspecified traffic patterns, BIG-IP AFM IPS engine may spend an excessive a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21771</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21771</guid>
    <pubDate>Wed, 14 Feb 2024 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-21771</strong></p>
  <p>For unspecified traffic patterns, BIG-IP AFM IPS engine may spend an excessive amount of time matching the traffic against signatures, resulting in Traffic Management Microkernel (TMM) restarting and traffic disruption.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21771">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-21763 – When BIG-IP AFM Device DoS or DoS profile is configured with NXDOMAIN attack vec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21763</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21763</guid>
    <pubDate>Wed, 14 Feb 2024 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-21763</strong></p>
  <p>When BIG-IP AFM Device DoS or DoS profile is configured with NXDOMAIN attack vector and bad actor detection, undisclosed queries can cause the Traffic Management Microkernel (TMM) to terminate.  NOTE: Software versions which have reached End of Technical Support (EoTS) are not evaluated</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21763">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-46748 – An authenticated SQL injection vulnerability exists in the BIG-IP Configuration ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46748</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46748</guid>
    <pubDate>Thu, 26 Oct 2023 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-46748</strong></p>
  <p>An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which   may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresses to execute arbitrary system commands.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46748">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-46747 – Undisclosed requests may bypass configuration utility authentication, allowing a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46747</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46747</guid>
    <pubDate>Thu, 26 Oct 2023 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-46747</strong></p>
  <p>Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46747">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-5450 – An insufficient verification of data vulnerability exists in BIG-IP Edge Client ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-5450</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-5450</guid>
    <pubDate>Tue, 10 Oct 2023 13:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-5450</strong></p>
  <p>An insufficient verification of data vulnerability exists in BIG-IP Edge Client Installer on macOS that may allow an attacker elevation of privileges during the installation process.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-345</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5450">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-45226 – The BIG-IP SPK TMM (Traffic Management Module) f5-debug-sidecar and f5-debug-ssh...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-45226</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-45226</guid>
    <pubDate>Tue, 10 Oct 2023 13:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-45226</strong></p>
  <p>The BIG-IP SPK TMM (Traffic Management Module) f5-debug-sidecar and f5-debug-sshd containers contains hardcoded credentials that may allow an attacker with the ability to intercept traffic to impersonate the SPK Secure Shell (SSH) server on those containers. This is only exposed when ssh debug is enabled.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45226">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-43746 – When running in Appliance mode, an authenticated user assigned the Administrator...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-43746</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-43746</guid>
    <pubDate>Tue, 10 Oct 2023 13:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-43746</strong></p>
  <p>When running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing BIG-IP external monitor on a BIG-IP system.  A successful exploit can allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-267</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-43746">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-43611 – The BIG-IP Edge Client Installer on macOS does not follow best practices for ele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-43611</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-43611</guid>
    <pubDate>Tue, 10 Oct 2023 13:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-43611</strong></p>
  <p>The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installation process.  This vulnerability is due to an incomplete fix for CVE-2023-38418.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-347</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-43611">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-42768 – When a non-admin user has been assigned an administrator role via an iControl RE...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-42768</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-42768</guid>
    <pubDate>Tue, 10 Oct 2023 13:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-42768</strong></p>
  <p>When a non-admin user has been assigned an administrator role via an iControl REST PUT request and later the user's role is reverted back to a non-admin role via the Configuration utility, tmsh, or iControl REST. BIG-IP non-admin user can still have access to iControl REST admin resource.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-42768">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-41373 – A directory traversal vulnerability exists in the BIG-IP Configuration Utility t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41373</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41373</guid>
    <pubDate>Tue, 10 Oct 2023 13:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-41373</strong></p>
  <p>A directory traversal vulnerability exists in the BIG-IP Configuration Utility that may allow an authenticated attacker to execute commands on the BIG-IP system. For BIG-IP system running in Appliance mode, a successful exploit can allow the attacker to cross a security boundary.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41373">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-40537 – An authenticated user's session cookie may remain valid for a limited time after...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40537</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40537</guid>
    <pubDate>Tue, 10 Oct 2023 13:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-40537</strong></p>
  <p>An authenticated user's session cookie may remain valid for a limited time after logging out from the BIG-IP Configuration utility on a multi-blade VIPRION platform.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40537">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-38418 – The BIG-IP Edge Client Installer on macOS does not follow best practices for ele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38418</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38418</guid>
    <pubDate>Wed, 02 Aug 2023 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-38418</strong></p>
  <p>The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installation process.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-347</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38418">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-38138 – A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed pa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38138</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38138</guid>
    <pubDate>Wed, 02 Aug 2023 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-38138</strong></p>
  <p>A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which allows an attacker to run JavaScript in the context of the currently logged-in user.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38138">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-36858 – An insufficient verification of data vulnerability exists in BIG-IP Edge Client ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-36858</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-36858</guid>
    <pubDate>Wed, 02 Aug 2023 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-36858</strong></p>
  <p>An insufficient verification of data vulnerability exists in BIG-IP Edge Client for Windows and macOS that may allow an attacker to modify its configured server list.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-345</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-36858">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-27378 – Multiple reflected cross-site scripting (XSS) vulnerabilities exist in undisclos...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-27378</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-27378</guid>
    <pubDate>Wed, 03 May 2023 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-27378</strong></p>
  <p>Multiple reflected cross-site scripting (XSS) vulnerabilities exist in undisclosed pages of the BIG-IP Configuration utility which allow an attacker to run JavaScript in the context of the currently logged-in user.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-27378">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-24461 – An improper certificate validation vulnerability exists in the BIG-IP Edge Clien...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-24461</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-24461</guid>
    <pubDate>Wed, 03 May 2023 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-24461</strong></p>
  <p>An improper certificate validation vulnerability exists in the BIG-IP Edge Client for Windows and macOS and may allow an attacker to impersonate a BIG-IP APM system.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24461">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-23555 – On BIG-IP Virtual Edition versions 15.1x beginning in 15.1.4 to before 15.1.8 an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-23555</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-23555</guid>
    <pubDate>Wed, 01 Feb 2023 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-23555</strong></p>
  <p>On BIG-IP Virtual Edition versions 15.1x beginning in 15.1.4 to before 15.1.8 and 14.1.x beginning in 14.1.5 to before 14.1.5.3, and BIG-IP SPK beginning in 1.5.0 to before 1.6.0, when FastL4 profile is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-665</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-23555">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-23552 – On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.0 before 15.1.8...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-23552</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-23552</guid>
    <pubDate>Wed, 01 Feb 2023 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-23552</strong></p>
  <p>On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.0 before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a BIG-IP Advanced WAF or BIG-IP ASM security policy is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-23552">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-22842 – On BIG-IP versions 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22842</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22842</guid>
    <pubDate>Wed, 01 Feb 2023 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-22842</strong></p>
  <p>On BIG-IP versions 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a SIP profile is configured on a Message Routing type virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22842">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-22839 – On BIG-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22839</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22839</guid>
    <pubDate>Wed, 01 Feb 2023 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-22839</strong></p>
  <p>On BIG-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all version of 13.1.x, when a DNS profile with the Rapid Response Mode setting enabled is configured on a virtual server with hardware SYN cookies enabled, undisclosed requests cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reache…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22839">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-22664 – On BIG-IP versions 17.0.x before 17.0.0.2 and 16.1.x before 16.1.3.3, and BIG-IP...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22664</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22664</guid>
    <pubDate>Wed, 01 Feb 2023 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-22664</strong></p>
  <p>On BIG-IP versions 17.0.x before 17.0.0.2 and 16.1.x before 16.1.3.3, and BIG-IP SPK starting in version 1.6.0, when a client-side HTTP/2 profile and the HTTP MRF Router option are enabled for a virtual server, undisclosed requests can cause an increase in memory resource utilization.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22664">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-22422 – On BIG-IP versions 17.0.x before 17.0.0.2 and 16.1.x before 16.1.3.3, when a HTT...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22422</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22422</guid>
    <pubDate>Wed, 01 Feb 2023 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-22422</strong></p>
  <p>On BIG-IP versions 17.0.x before 17.0.0.2 and 16.1.x before 16.1.3.3, when a HTTP profile with the non-default Enforcement options of Enforce HTTP Compliance and Unknown Methods: Reject are configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluat…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22422">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-22374 – A format string vulnerability exists in iControl SOAP that allows an authenticat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22374</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22374</guid>
    <pubDate>Wed, 01 Feb 2023 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-22374</strong></p>
  <p>A format string vulnerability exists in iControl SOAP that allows an authenticated attacker to crash the iControl SOAP CGI process or, potentially execute arbitrary code. In appliance mode BIG-IP, a successful exploit of this vulnerability can allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-134</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22374">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-22358 – In versions beginning with 7.2.2 to before 7.2.3.1, a DLL hijacking vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22358</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22358</guid>
    <pubDate>Wed, 01 Feb 2023 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-22358</strong></p>
  <p>In versions beginning with 7.2.2 to before 7.2.3.1, a DLL hijacking vulnerability exists in the BIG-IP Edge Client Windows Installer.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22358">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-22341 – On version 14.1.x before 14.1.5.3, and all versions of 13.1.x, when the BIG-IP A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22341</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22341</guid>
    <pubDate>Wed, 01 Feb 2023 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-22341</strong></p>
  <p>On version 14.1.x before 14.1.5.3, and all versions of 13.1.x, when the BIG-IP APM system is configured with all the following elements, undisclosed requests may cause the Traffic Management Microkernel (TMM) to terminate:    *  An OAuth Server that references an OAuth Provider   *  An OAuth profile with the Authorization Endpoint set to '/'   *  An access profile that references the above OAuth…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22341">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-22340 – On BIG-IP versions 16.1.x before 16.1.3.3, 15.1.x before 15.1.8, 14.1.x before 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22340</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22340</guid>
    <pubDate>Wed, 01 Feb 2023 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-22340</strong></p>
  <p>On BIG-IP versions 16.1.x before 16.1.3.3, 15.1.x before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a SIP profile is configured on a Message Routing type virtual server, undisclosed traffic can cause TMM to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22340">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-22281 – On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22281</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22281</guid>
    <pubDate>Wed, 01 Feb 2023 18:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-22281</strong></p>
  <p>On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a BIG-IP AFM NAT policy with a destination NAT rule is configured on a FastL4 virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are n…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22281">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-41800 – In all versions of BIG-IP, when running in Appliance mode, an authenticated user...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41800</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41800</guid>
    <pubDate>Wed, 07 Dec 2022 04:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-41800</strong></p>
  <p>In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary.    Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41800">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-41622 – In all versions, 

BIG-IP and BIG-IQ are vulnerable to cross-site request forger...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41622</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41622</guid>
    <pubDate>Wed, 07 Dec 2022 04:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-41622</strong></p>
  <p>In all versions,   BIG-IP and BIG-IQ are vulnerable to cross-site request forgery (CSRF) attacks through iControl SOAP.    Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41622">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-41833 – In all BIG-IP 13.1.x versions, when an iRule containing the HTTP::collect comman...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41833</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41833</guid>
    <pubDate>Wed, 19 Oct 2022 22:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-41833</strong></p>
  <p>In all BIG-IP 13.1.x versions, when an iRule containing the HTTP::collect command is configured on a virtual server, undisclosed requests can cause Traffic Management Microkernel (TMM) to terminate.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41833">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-41832 – In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41832</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41832</guid>
    <pubDate>Wed, 19 Oct 2022 22:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-41832</strong></p>
  <p>In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and 13.1.x before 13.1.5.1, when a SIP profile is configured on a virtual server, undisclosed messages can cause an increase in memory resource utilization.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41832">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-41806 – In versions 16.1.x before 16.1.3.2 and 15.1.x before 15.1.5.1, when BIG-IP AFM N...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41806</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41806</guid>
    <pubDate>Wed, 19 Oct 2022 22:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-41806</strong></p>
  <p>In versions 16.1.x before 16.1.3.2 and 15.1.x before 15.1.5.1, when BIG-IP AFM Network Address Translation policy with IPv6/IPv4 translation rules is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41806">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-41787 – In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41787</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41787</guid>
    <pubDate>Wed, 19 Oct 2022 22:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-41787</strong></p>
  <p>In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and 13.1.x before 13.1.5.1, when DNS profile is configured on a virtual server with DNS Express enabled, undisclosed DNS queries with DNSSEC can cause TMM to terminate.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41787">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-41691 – When a BIG-IP Advanced WAF/ASM security policy is configured on a virtual server...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41691</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41691</guid>
    <pubDate>Wed, 19 Oct 2022 22:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-41691</strong></p>
  <p>When a BIG-IP Advanced WAF/ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-763</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41691">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-41624 – In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.2, 15.1.x before...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41624</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41624</guid>
    <pubDate>Wed, 19 Oct 2022 22:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-41624</strong></p>
  <p>In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.2, 15.1.x before 15.1.7, 14.1.x before 14.1.5.2, and 13.1.x before 13.1.5.1, when a sideband iRule is configured on a virtual server, undisclosed traffic can cause an increase in memory resource utilization.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41624">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-41617 – In versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41617</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41617</guid>
    <pubDate>Wed, 19 Oct 2022 22:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-41617</strong></p>
  <p>In versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and 13.1.x before 13.1.5.1, When the Advanced WAF / ASM module is provisioned, an authenticated remote code execution vulnerability exists in the BIG-IP iControl REST interface.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41617">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-35735 – In BIG-IP Versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-35735</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-35735</guid>
    <pubDate>Thu, 04 Aug 2022 18:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-35735</strong></p>
  <p>In BIG-IP Versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, an authenticated attacker with Resource Administrator or Manager privileges can create or modify existing monitor objects in the Configuration utility in an undisclosed manner leading to a privilege escalation. Note: Software versions which have reached End of Technical Support (…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-35735">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
