Vulnerabilities > F5

DATE CVE VULNERABILITY TITLE RISK
2020-12-24 CVE-2020-27725 Memory Leak vulnerability in F5 products
In version 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2 of BIG-IP DNS, GTM, and Link Controller, zxfrd leaks memory when listing DNS zones.
network
low complexity
f5 CWE-401
4.3
2020-12-24 CVE-2020-27724 Resource Exhaustion vulnerability in F5 Big-Ip Access Policy Manager
In BIG-IP APM versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, on systems running more than one TMM instance, authenticated VPN users may consume excessive resources by sending specially-crafted malicious traffic over the tunnel.
network
low complexity
f5 CWE-400
6.5
2020-12-24 CVE-2020-27721 Unspecified vulnerability in F5 products
In versions 16.0.0-16.0.0.1, 15.1.0-15.1.1, 14.1.0-14.1.3, 13.1.0-13.1.3.5, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, in a BIG-IP DNS / BIG-IP LTM GSLB deployment, under certain circumstances, the BIG-IP DNS system may stop using a BIG-IP LTM virtual server for DNS response.
network
low complexity
f5
7.5
2020-12-24 CVE-2020-27718 Unspecified vulnerability in F5 products
When a BIG-IP ASM or Advanced WAF system running version 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, or 11.6.1-11.6.5.2 processes requests with JSON payload, an unusually large number of parameters can cause excessive CPU usage in the BIG-IP ASM bd process.
network
low complexity
f5
7.5
2020-12-11 CVE-2020-27730 Path Traversal vulnerability in multiple products
In versions 3.0.0-3.9.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller Agent does not use absolute paths when calling system utilities.
network
low complexity
f5 netapp CWE-22
critical
9.8
2020-12-11 CVE-2020-5950 Cross-site Scripting vulnerability in F5 Big-Ip Advanced Firewall Manager
On BIG-IP 14.1.0-14.1.2.6, undisclosed endpoints in iControl REST allow for a reflected XSS attack, which could lead to a complete compromise of the BIG-IP system if the victim user is granted the admin role.
network
low complexity
f5 CWE-79
5.3
2020-12-11 CVE-2020-5949 Unspecified vulnerability in F5 products
On BIG-IP versions 14.0.0-14.0.1 and 13.1.0-13.1.3.4, certain traffic pattern sent to a virtual server configured with an FTP profile can cause the FTP channel to break.
network
low complexity
f5
7.5
2020-12-11 CVE-2020-5948 Cross-site Scripting vulnerability in F5 products
On BIG-IP versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.2.7, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, undisclosed endpoints in iControl REST allow for a reflected XSS attack, which could lead to a complete compromise of the BIG-IP system if the victim user is granted the admin role.
network
low complexity
f5 CWE-79
critical
9.6
2020-12-11 CVE-2020-27713 Memory Leak vulnerability in F5 Big-Ip Advanced Firewall Manager 13.1.3.4
In certain configurations on version 13.1.3.4, when a BIG-IP AFM HTTP security profile is applied to a virtual server and the BIG-IP system receives a request with specific characteristics, the connection is reset and the Traffic Management Microkernel (TMM) leaks memory.
network
low complexity
f5 CWE-401
7.5
2020-11-19 CVE-2020-5947 Unspecified vulnerability in F5 products
In versions 16.0.0-16.0.0.1 and 15.1.0-15.1.1, on specific BIG-IP platforms, attackers may be able to obtain TCP sequence numbers from the BIG-IP system that can be reused in future connections with the same source and destination port and IP numbers.
network
low complexity
f5
4.3