F5
F5 Traffix Signaling Delivery Controller: vulnerabilidades y CVE
F5 Traffix Signaling Delivery Controller tiene 31 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 3 figuran en el catálogo de explotación activa de CISA.
CVE31
Últimos 12 meses0
Críticas2
Explotadas activamente3
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2018-14634 | Alta (7.8) | 15% | ⚠ Explotación activa | 25 sept 2018 | An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on… |
| CVE-2014-6271 | Crítica (9.8) | 100% | ⚠ Explotación activa | 24 sept 2014 | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by… |
| CVE-2014-7169 | Crítica (9.8) | 100% | ⚠ Explotación activa | 25 sept 2014 | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-27880 | Media (4.8) | 0.48% | — | 5 may 2022 | On F5 Traffix SDC 5.2.x versions prior to 5.2.2 and 5.1.x versions prior to 5.1.35, a stored Cross-Site Scripting (XSS) vulnerability exists in an undisclosed page of the Traffix SDC Configuration utility that allows an… |
| CVE-2022-27662 | Media (4.8) | 0.48% | — | 5 may 2022 | On F5 Traffix SDC 5.2.x versions prior to 5.2.2 and 5.1.x versions prior to 5.1.35, a stored Cross-Site Template Injection vulnerability exists in an undisclosed page of the Traffix SDC Configuration utility that allows… |
| CVE-2002-20001 | Alta (7.5) | 25% | — | 11 nov 2021 | The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation… |
| CVE-2020-5854 | Media (5.9) | 0.81% | — | 6 feb 2020 | On BIG-IP 15.0.0-15.0.1.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.6.0-11.6.5.1, the tmm crashes under certain circumstances when using the connector profile if a specific sequence of… |
| CVE-2018-16229 | Alta (7.5) | 6.8% | — | 3 oct 2019 | The DCCP parser in tcpdump before 4.9.3 has a buffer over-read in print-dccp.c:dccp_print_option(). |
| CVE-2018-14882 | Alta (7.5) | 3.9% | — | 3 oct 2019 | The ICMPv6 parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp6.c. |
| CVE-2018-14880 | Alta (7.5) | 5.3% | — | 3 oct 2019 | The OSPFv3 parser in tcpdump before 4.9.3 has a buffer over-read in print-ospf6.c:ospf6_print_lshdr(). |
| CVE-2018-14879 | Alta (7) | 4.7% | — | 3 oct 2019 | The command-line argument parser in tcpdump before 4.9.3 has a buffer overflow in tcpdump.c:get_next_file(). |
| CVE-2018-14469 | Alta (7.5) | 5.3% | — | 3 oct 2019 | The IKEv1 parser in tcpdump before 4.9.3 has a buffer over-read in print-isakmp.c:ikev1_n_print(). |
| CVE-2018-14468 | Alta (7.5) | 4.0% | — | 3 oct 2019 | The FRF.16 parser in tcpdump before 4.9.3 has a buffer over-read in print-fr.c:mfr_print(). |
| CVE-2018-14465 | Alta (7.5) | 4.1% | — | 3 oct 2019 | The RSVP parser in tcpdump before 4.9.3 has a buffer over-read in print-rsvp.c:rsvp_obj_print(). |
| CVE-2018-14463 | Alta (7.5) | 4.7% | — | 3 oct 2019 | The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 2, a different vulnerability than CVE-2019-15167. |
| CVE-2018-14462 | Alta (7.5) | 4.0% | — | 3 oct 2019 | The ICMP parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp.c:icmp_print(). |
| CVE-2019-16714 | Alta (7.5) | 2.7% | — | 23 sept 2019 | In the Linux kernel before 5.2.14, rds6_inc_info_copy in net/rds/recv.c allows attackers to obtain sensitive information from kernel stack memory because tos and flags fields are not initialized. |
| CVE-2019-13565 | Alta (7.5) | 5.0% | — | 26 jul 2019 | An issue was discovered in OpenLDAP 2.x before 2.4.48. When using SASL authentication and session encryption, and relying on the SASL security layers in slapd access controls, it is possible to obtain access that would… |
| CVE-2019-13050 | Alta (7.5) | 2.5% | — | 29 jun 2019 | Interaction between the sks-keyserver code through 1.2.0 of the SKS keyserver network, and GnuPG through 2.2.16, makes it risky to have a GnuPG keyserver configuration line referring to a host on the SKS keyserver… |
| CVE-2019-11479 | Alta (7.5) | 92% | — | 19 jun 2019 | Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows a remote peer to fragment TCP resend queues significantly more than if a larger MSS were enforced. A remote attacker… |
| CVE-2019-11478 | Alta (7.5) | 95% | — | 19 jun 2019 | Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker… |
| CVE-2019-11477 | Alta (7.5) | 99% | — | 19 jun 2019 | Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). A remote attacker could use this to… |
| CVE-2019-5436 | Alta (7.8) | 50% | — | 28 may 2019 | A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1. |
| CVE-2018-20836 | Alta (8.1) | 5.1% | — | 7 may 2019 | An issue was discovered in the Linux kernel before 4.20. There is a race condition in smp_task_timedout() and smp_task_done() in drivers/scsi/libsas/sas_expander.c, leading to a use-after-free. |
| CVE-2019-1559 | Media (5.9) | 17% | — | 27 feb 2019 | If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte… |
| CVE-2019-9077 | Alta (7.8) | 2.0% | — | 24 feb 2019 | An issue was discovered in GNU Binutils 2.32. It is a heap-based buffer overflow in process_mips_specific in readelf.c via a malformed MIPS option section. |
| CVE-2019-9070 | Alta (7.8) | 1.6% | — | 24 feb 2019 | An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. It is a heap-based buffer over-read in d_expression_1 in cp-demangle.c after many recursive calls. |
| CVE-2018-1320 | Alta (7.5) | 8.2% | — | 7 ene 2019 | Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.TSaslTransport class. An assert used to determine if the SASL… |
| CVE-2018-20657 | Alta (7.5) | 4.0% | — | 2 ene 2019 | The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, has a memory leak via a crafted string, leading to a denial of service (memory consumption), as demonstrated by… |
| CVE-2018-20002 | Media (5.5) | 1.8% | — | 10 dic 2018 | The _bfd_generic_read_minisymbols function in syms.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31, has a memory leak via a crafted ELF file, leading to a denial of… |
| CVE-2018-14634 | Alta (7.8) | 15% | ⚠ Explotación activa | 25 sept 2018 | An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on… |
| CVE-2015-5738 | Alta (7.5) | 2.4% | — | 26 jul 2016 | The RSA-CRT implementation in the Cavium Software Development Kit (SDK) 2.x, when used on OCTEON II CN6xxx Hardware on Linux to support TLS with Perfect Forward Secrecy (PFS), makes it easier for remote attackers to… |
| CVE-2014-7169 | Crítica (9.8) | 100% | ⚠ Explotación activa | 25 sept 2014 | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de F5
Big-ip Access Policy Manager · 630Big-ip Application Security Manager · 581Big-ip Advanced Firewall Manager · 552Big-ip Local Traffic Manager · 541Big-ip Policy Enforcement Manager · 533Big-ip Link Controller · 525Big-ip Application Acceleration Manager · 524Big-ip Analytics · 511Big-ip Global Traffic Manager · 490Big-ip Domain Name System · 469Big-ip Fraud Protection Service · 405Big-ip Webaccelerator · 297