F5
F5 Big-iq Centralized Management: vulnerabilities and CVEs
F5 Big-iq Centralized Management has 85 published vulnerabilities, 8 of them in the last 12 months. 8 are rated critical and 3 are listed by CISA as actively exploited.
CVEs85
Last 12 months8
Critical8
Actively exploited3
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-14634 | High (7.8) | 15% | ⚠ Active exploitation | Sep 25, 2018 | An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on… |
| CVE-2014-0196 | Medium (5.5) | 22% | ⚠ Active exploitation | May 7, 2014 | The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory… |
| CVE-2021-22986 | Critical (9.8) | 100% | ⚠ Active exploitation | Mar 31, 2021 | On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST… |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-42406 | High (8.5) | 0.25% | — | May 13, 2026 | A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands.… |
| CVE-2026-41959 | High (7.1) | 0.28% | — | May 13, 2026 | Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) network diagnostics commands and in BIG-IP iControl REST. These vulnerabilities may allow an authenticated attacker to view… |
| CVE-2026-41957 | High (8.7) | 0.87% | — | May 13, 2026 | An authenticated remote code execution vulnerability through undisclosed vectors exists in the BIG-IP and BIG-IQ Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not… |
| CVE-2026-41954 | Medium (6.9) | 0.40% | — | May 13, 2026 | Sensitive information disclosure vulnerability exists in the undisclosed iControl REST endpoint and TMOS Shell (tmsh) command which may allow an authenticated attacker with resource administrator role privileges to view… |
| CVE-2026-41219 | High (7.1) | 0.38% | — | May 13, 2026 | An improper sanitization vulnerability exists in the BIG-IP QKView utility that allows a low-privileged attacker to read sensitive information from a QKView file. Note: Software versions which have reached End of… |
| CVE-2026-40698 | High (8.5) | 0.41% | — | May 13, 2026 | A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can create SNMP configuration objects through iControl REST or the TMOS… |
| CVE-2026-32643 | High (8.5) | 0.26% | — | May 13, 2026 | A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands.… |
| CVE-2026-20916 | High (7.2) | 0.37% | — | May 13, 2026 | An authenticated iControl REST user with low privileges can create or modify arbitrary files through an undisclosed iControl REST endpoint on the BIG-IQ system. Note: Software versions which have reached End of… |
| CVE-2024-47139 | Medium (4.8) | 0.58% | — | Oct 16, 2024 | A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IQ Configuration utility that allows an attacker with the Administrator role to run JavaScript in the context of the currently… |
| CVE-2024-24775 | High (7.5) | 0.52% | — | Feb 14, 2024 | When a virtual server is enabled with VLAN group and SNAT listener is configured, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of… |
| CVE-2024-23979 | High (7.5) | 0.34% | — | Feb 14, 2024 | When SSL Client Certificate LDAP or Certificate Revocation List Distribution Point (CRLDP) authentication profile is configured on a virtual server, undisclosed requests can cause an increase in CPU resource… |
| CVE-2024-23976 | Medium (6) | 0.17% | — | Feb 14, 2024 | When running in Appliance mode, an authenticated attacker assigned the Administrator role may be able to bypass Appliance mode restrictions utilizing iAppsLX templates on a BIG-IP system. Note: Software versions which… |
| CVE-2024-23314 | High (7.5) | 0.52% | — | Feb 14, 2024 | When HTTP/2 is configured on BIG-IP or BIG-IP Next SPK systems, undisclosed responses can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support… |
| CVE-2024-22389 | High (7.2) | 0.50% | — | Feb 14, 2024 | When BIG-IP is deployed in high availability (HA) and an iControl REST API token is updated, the change does not sync to the peer device. Note: Software versions which have reached End of Technical Support (EoTS) are… |
| CVE-2024-22093 | High (8.7) | 0.83% | — | Feb 14, 2024 | When running in appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint on multi-bladed systems. A successful exploit can allow the attacker to cross a… |
| CVE-2024-21782 | Medium (6.7) | 0.18% | — | Feb 14, 2024 | BIG-IP or BIG-IQ Resource Administrators and Certificate Managers who have access to the secure copy (scp) utility but do not have access to Advanced shell (bash) can execute arbitrary commands with a specially crafted… |
| CVE-2023-43485 | Medium (5.5) | 0.17% | — | Oct 10, 2023 | When TACACS+ audit forwarding is configured on BIG-IP or BIG-IQ system, sharedsecret is logged in plaintext in the audit log. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. |
| CVE-2023-41964 | Medium (6.5) | 0.24% | — | Oct 10, 2023 | The BIG-IP and BIG-IQ systems do not encrypt some sensitive information written to Database (DB) variables. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. |
| CVE-2023-38419 | Medium (4.3) | 0.55% | — | Aug 2, 2023 | An authenticated attacker with guest privileges or higher can cause the iControl SOAP process to terminate by sending undisclosed requests. Note: Software versions which have reached End of Technical Support (EoTS) are… |
| CVE-2023-29240 | Medium (5.4) | 0.40% | — | May 3, 2023 | An authenticated attacker granted a Viewer or Auditor role on a BIG-IQ can upload arbitrary files using an undisclosed iControl REST endpoint. Note: Software versions which have reached End of Technical Support (EoTS)… |
| CVE-2022-41622 | High (8.8) | 92% | — | Dec 7, 2022 | In all versions, BIG-IP and BIG-IQ are vulnerable to cross-site request forgery (CSRF) attacks through iControl SOAP. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. |
| CVE-2022-41770 | Medium (6.5) | 0.65% | — | Oct 19, 2022 | In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.7, 14.1.x before 14.1.5.1, and all versions of 13.1.x, and BIG-IQ all versions of 8.x and 7.x, an authenticated iControl REST user… |
| CVE-2022-35728 | Critical (9.8) | 0.67% | — | Aug 4, 2022 | In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, and BIG-IQ version 8.x before 8.2.0 and all versions of 7.x, an… |
| CVE-2022-34851 | Medium (6.5) | 0.74% | — | Aug 4, 2022 | In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, and BIG-IQ Centralized Management all versions of 8.x, an authenticated… |
| CVE-2022-34844 | High (7.5) | 0.72% | — | Aug 4, 2022 | In BIG-IP Versions 16.1.x before 16.1.3.1 and 15.1.x before 15.1.6.1, and all versions of BIG-IQ 8.x, when the Data Plane Development Kit (DPDK)/Elastic Network Adapter (ENA) driver is used with BIG-IP or BIG-IQ on… |
| CVE-2022-29479 | Medium (5.3) | 0.92% | — | May 5, 2022 | On F5 BIG-IP 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, and F5 BIG-IQ Centralized Management all versions of 8.x and… |
| CVE-2022-26340 | Medium (4.9) | 0.47% | — | May 5, 2022 | On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, and F5 BIG-IQ Centralized… |
| CVE-2022-23023 | Medium (6.5) | 0.90% | — | Jan 25, 2022 | On BIG-IP version 16.1.x before 16.1.2.1, 15.1.x before 15.1.5, 14.1.x before 14.1.4.5, and all versions of 13.1.x and 12.1.x, and BIG-IQ all versions of 8.x and 7.x, undisclosed requests by an authenticated iControl… |
| CVE-2022-23009 | High (7.2) | 1.1% | — | Jan 25, 2022 | On BIG-IQ Centralized Management 8.x before 8.1.0, an authenticated administrative role user on a BIG-IQ managed BIG-IP device can access other BIG-IP devices managed by the same BIG-IQ system. Note: Software versions… |
| CVE-2002-20001 | High (7.5) | 25% | — | Nov 11, 2021 | The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation… |
Other products by F5
Big-ip Access Policy Manager · 630Big-ip Application Security Manager · 581Big-ip Advanced Firewall Manager · 552Big-ip Local Traffic Manager · 541Big-ip Policy Enforcement Manager · 533Big-ip Link Controller · 525Big-ip Application Acceleration Manager · 524Big-ip Analytics · 511Big-ip Global Traffic Manager · 490Big-ip Domain Name System · 469Big-ip Fraud Protection Service · 405Big-ip Webaccelerator · 297