F5
F5 Big-iq Centralized Management: vulnerabilidades y CVE
F5 Big-iq Centralized Management tiene 85 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 8 son críticas y 3 figuran en el catálogo de explotación activa de CISA.
CVE85
Últimos 12 meses8
Críticas8
Explotadas activamente3
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2018-14634 | Alta (7.8) | 15% | ⚠ Explotación activa | 25 sept 2018 | An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on… |
| CVE-2014-0196 | Media (5.5) | 22% | ⚠ Explotación activa | 7 may 2014 | The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory… |
| CVE-2021-22986 | Crítica (9.8) | 100% | ⚠ Explotación activa | 31 mar 2021 | On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-42406 | Alta (8.5) | 0.25% | — | 13 may 2026 | A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands.… |
| CVE-2026-41959 | Alta (7.1) | 0.28% | — | 13 may 2026 | Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) network diagnostics commands and in BIG-IP iControl REST. These vulnerabilities may allow an authenticated attacker to view… |
| CVE-2026-41957 | Alta (8.7) | 0.87% | — | 13 may 2026 | An authenticated remote code execution vulnerability through undisclosed vectors exists in the BIG-IP and BIG-IQ Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not… |
| CVE-2026-41954 | Media (6.9) | 0.40% | — | 13 may 2026 | Sensitive information disclosure vulnerability exists in the undisclosed iControl REST endpoint and TMOS Shell (tmsh) command which may allow an authenticated attacker with resource administrator role privileges to view… |
| CVE-2026-41219 | Alta (7.1) | 0.38% | — | 13 may 2026 | An improper sanitization vulnerability exists in the BIG-IP QKView utility that allows a low-privileged attacker to read sensitive information from a QKView file. Note: Software versions which have reached End of… |
| CVE-2026-40698 | Alta (8.5) | 0.41% | — | 13 may 2026 | A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can create SNMP configuration objects through iControl REST or the TMOS… |
| CVE-2026-32643 | Alta (8.5) | 0.26% | — | 13 may 2026 | A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands.… |
| CVE-2026-20916 | Alta (7.2) | 0.37% | — | 13 may 2026 | An authenticated iControl REST user with low privileges can create or modify arbitrary files through an undisclosed iControl REST endpoint on the BIG-IQ system. Note: Software versions which have reached End of… |
| CVE-2024-47139 | Media (4.8) | 0.58% | — | 16 oct 2024 | A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IQ Configuration utility that allows an attacker with the Administrator role to run JavaScript in the context of the currently… |
| CVE-2024-24775 | Alta (7.5) | 0.52% | — | 14 feb 2024 | When a virtual server is enabled with VLAN group and SNAT listener is configured, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of… |
| CVE-2024-23979 | Alta (7.5) | 0.34% | — | 14 feb 2024 | When SSL Client Certificate LDAP or Certificate Revocation List Distribution Point (CRLDP) authentication profile is configured on a virtual server, undisclosed requests can cause an increase in CPU resource… |
| CVE-2024-23976 | Media (6) | 0.17% | — | 14 feb 2024 | When running in Appliance mode, an authenticated attacker assigned the Administrator role may be able to bypass Appliance mode restrictions utilizing iAppsLX templates on a BIG-IP system. Note: Software versions which… |
| CVE-2024-23314 | Alta (7.5) | 0.52% | — | 14 feb 2024 | When HTTP/2 is configured on BIG-IP or BIG-IP Next SPK systems, undisclosed responses can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support… |
| CVE-2024-22389 | Alta (7.2) | 0.50% | — | 14 feb 2024 | When BIG-IP is deployed in high availability (HA) and an iControl REST API token is updated, the change does not sync to the peer device. Note: Software versions which have reached End of Technical Support (EoTS) are… |
| CVE-2024-22093 | Alta (8.7) | 0.83% | — | 14 feb 2024 | When running in appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint on multi-bladed systems. A successful exploit can allow the attacker to cross a… |
| CVE-2024-21782 | Media (6.7) | 0.18% | — | 14 feb 2024 | BIG-IP or BIG-IQ Resource Administrators and Certificate Managers who have access to the secure copy (scp) utility but do not have access to Advanced shell (bash) can execute arbitrary commands with a specially crafted… |
| CVE-2023-43485 | Media (5.5) | 0.17% | — | 10 oct 2023 | When TACACS+ audit forwarding is configured on BIG-IP or BIG-IQ system, sharedsecret is logged in plaintext in the audit log. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. |
| CVE-2023-41964 | Media (6.5) | 0.24% | — | 10 oct 2023 | The BIG-IP and BIG-IQ systems do not encrypt some sensitive information written to Database (DB) variables. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. |
| CVE-2023-38419 | Media (4.3) | 0.55% | — | 2 ago 2023 | An authenticated attacker with guest privileges or higher can cause the iControl SOAP process to terminate by sending undisclosed requests. Note: Software versions which have reached End of Technical Support (EoTS) are… |
| CVE-2023-29240 | Media (5.4) | 0.40% | — | 3 may 2023 | An authenticated attacker granted a Viewer or Auditor role on a BIG-IQ can upload arbitrary files using an undisclosed iControl REST endpoint. Note: Software versions which have reached End of Technical Support (EoTS)… |
| CVE-2022-41622 | Alta (8.8) | 92% | — | 7 dic 2022 | In all versions, BIG-IP and BIG-IQ are vulnerable to cross-site request forgery (CSRF) attacks through iControl SOAP. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. |
| CVE-2022-41770 | Media (6.5) | 0.65% | — | 19 oct 2022 | In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.7, 14.1.x before 14.1.5.1, and all versions of 13.1.x, and BIG-IQ all versions of 8.x and 7.x, an authenticated iControl REST user… |
| CVE-2022-35728 | Crítica (9.8) | 0.67% | — | 4 ago 2022 | In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, and BIG-IQ version 8.x before 8.2.0 and all versions of 7.x, an… |
| CVE-2022-34851 | Media (6.5) | 0.74% | — | 4 ago 2022 | In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, and BIG-IQ Centralized Management all versions of 8.x, an authenticated… |
| CVE-2022-34844 | Alta (7.5) | 0.72% | — | 4 ago 2022 | In BIG-IP Versions 16.1.x before 16.1.3.1 and 15.1.x before 15.1.6.1, and all versions of BIG-IQ 8.x, when the Data Plane Development Kit (DPDK)/Elastic Network Adapter (ENA) driver is used with BIG-IP or BIG-IQ on… |
| CVE-2022-29479 | Media (5.3) | 0.92% | — | 5 may 2022 | On F5 BIG-IP 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, and F5 BIG-IQ Centralized Management all versions of 8.x and… |
| CVE-2022-26340 | Media (4.9) | 0.47% | — | 5 may 2022 | On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, and F5 BIG-IQ Centralized… |
| CVE-2022-23023 | Media (6.5) | 0.90% | — | 25 ene 2022 | On BIG-IP version 16.1.x before 16.1.2.1, 15.1.x before 15.1.5, 14.1.x before 14.1.4.5, and all versions of 13.1.x and 12.1.x, and BIG-IQ all versions of 8.x and 7.x, undisclosed requests by an authenticated iControl… |
| CVE-2022-23009 | Alta (7.2) | 1.1% | — | 25 ene 2022 | On BIG-IQ Centralized Management 8.x before 8.1.0, an authenticated administrative role user on a BIG-IQ managed BIG-IP device can access other BIG-IP devices managed by the same BIG-IQ system. Note: Software versions… |
| CVE-2002-20001 | Alta (7.5) | 25% | — | 11 nov 2021 | The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation… |
Otros productos de F5
Big-ip Access Policy Manager · 630Big-ip Application Security Manager · 581Big-ip Advanced Firewall Manager · 552Big-ip Local Traffic Manager · 541Big-ip Policy Enforcement Manager · 533Big-ip Link Controller · 525Big-ip Application Acceleration Manager · 524Big-ip Analytics · 511Big-ip Global Traffic Manager · 490Big-ip Domain Name System · 469Big-ip Fraud Protection Service · 405Big-ip Webaccelerator · 297