Vulnerabilities > F5

DATE CVE VULNERABILITY TITLE RISK
2021-09-14 CVE-2021-23050 Unspecified vulnerability in F5 products
On BIG-IP Advanced WAF and BIG-IP ASM version 16.0.x before 16.0.1.2 and 15.1.x before 15.1.3 and NGINX App Protect on all versions before 3.5.0, when a cross-site request forgery (CSRF)-enabled policy is configured on a virtual server, an undisclosed HTML response may cause the bd process to terminate.
network
low complexity
f5
7.5
2021-09-14 CVE-2021-23051 Unspecified vulnerability in F5 products
On BIG-IP versions 15.1.0.4 through 15.1.3, when the Data Plane Development Kit (DPDK)/Elastic Network Adapter (ENA) driver is used with BIG-IP on Amazon Web Services (AWS) systems, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate.
network
low complexity
f5
7.5
2021-09-14 CVE-2021-23052 Open Redirect vulnerability in F5 Big-Ip Access Policy Manager
On version 14.1.x before 14.1.4.4 and all versions of 13.1.x, an open redirect vulnerability exists on virtual servers enabled with a BIG-IP APM access policy.
network
low complexity
f5 CWE-601
6.1
2021-09-14 CVE-2021-23053 Allocation of Resources Without Limits or Throttling vulnerability in F5 products
On version 15.1.x before 15.1.3, 14.1.x before 14.1.3.1, and 13.1.x before 13.1.3.6, when the brute force protection feature of BIG-IP Advanced WAF or BIG-IP ASM is enabled on a virtual server and the virtual server is under brute force attack, the MySQL database may run out of disk space due to lack of row limit on undisclosed tables in the MYSQL database.
network
low complexity
f5 CWE-770
5.3
2021-06-10 CVE-2021-23022 Incorrect Permission Assignment for Critical Resource vulnerability in F5 products
On version 7.2.1.x before 7.2.1.3 and 7.1.x before 7.1.9.9 Update 1, the BIG-IP Edge Client Windows Installer Service's temporary folder has weak file and folder permissions.
local
low complexity
f5 CWE-732
7.8
2021-06-10 CVE-2021-23023 Uncontrolled Search Path Element vulnerability in F5 Big-Ip Access Policy Manager
On version 7.2.1.x before 7.2.1.3 and 7.1.x before 7.1.9.9 Update 1, a DLL hijacking issue exists in cachecleaner.dll included in the BIG-IP Edge Client Windows Installer.
local
low complexity
f5 CWE-427
7.8
2021-06-10 CVE-2021-23024 Unspecified vulnerability in F5 Big-Iq Centralized Management
On version 8.0.x before 8.0.0.1, and all 6.x and 7.x versions, the BIG-IQ Configuration utility has an authenticated remote command execution vulnerability in undisclosed pages.
network
low complexity
f5
7.2
2021-06-06 CVE-2017-20005 Integer Overflow or Wraparound vulnerability in multiple products
NGINX before 1.13.6 has a buffer overflow for years that exceed four digits, as demonstrated by a file with a modification date in 1969 that causes an integer overflow (or a false modification date far in the future), when encountered by the autoindex module.
network
low complexity
f5 debian CWE-190
critical
9.8
2021-06-01 CVE-2021-23017 A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact.
network
high complexity
f5 openresty fedoraproject netapp oracle
7.7
2021-06-01 CVE-2021-23019 Insufficiently Protected Credentials vulnerability in F5 Nginx Controller
The NGINX Controller 2.0.0 thru 2.9.0 and 3.x before 3.15.0 Administrator password may be exposed in the systemd.txt file that is included in the NGINX support package.
local
low complexity
f5 CWE-522
7.8