Vulnerabilities > F5

DATE CVE VULNERABILITY TITLE RISK
2020-02-06 CVE-2020-5856 Improper Input Validation vulnerability in F5 products
On BIG-IP 15.0.0-15.0.1.1 and 14.1.0-14.1.2.2, while processing specifically crafted traffic using the default 'xnet' driver, Virtual Edition instances hosted in Amazon Web Services (AWS) may experience a TMM restart.
network
low complexity
f5 CWE-20
5.0
2020-02-06 CVE-2020-5855 Incorrect Authorization vulnerability in F5 Big-Ip Access Policy Manager
When the Windows Logon Integration feature is configured for all versions of BIG-IP Edge Client for Windows, unauthorized users who have physical access to an authorized user's machine can get shell access under unprivileged user.
local
low complexity
f5 CWE-863
4.6
2020-02-06 CVE-2020-5854 Unspecified vulnerability in F5 products
On BIG-IP 15.0.0-15.0.1.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.6.0-11.6.5.1, the tmm crashes under certain circumstances when using the connector profile if a specific sequence of connections are made.
network
high complexity
f5
5.9
2020-01-14 CVE-2020-5853 Cross-site Scripting vulnerability in F5 Big-Ip Access Policy Manager
In BIG-IP APM portal access on versions 15.0.0-15.1.0, 14.0.0-14.1.2.3, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, when backend servers serve HTTP pages with special JavaScript code, this can lead to internal portal access name conflict.
network
f5 CWE-79
3.5
2020-01-14 CVE-2020-5852 Unspecified vulnerability in F5 products
Undisclosed traffic patterns received may cause a disruption of service to the Traffic Management Microkernel (TMM).
network
low complexity
f5
5.0
2020-01-14 CVE-2020-5851 Unspecified vulnerability in F5 products
On impacted versions and platforms the Trusted Platform Module (TPM) system integrity check cannot detect modifications to specific system components.
local
low complexity
f5
2.1
2020-01-09 CVE-2019-20372 HTTP Request Smuggling vulnerability in multiple products
NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.
4.3
2020-01-08 CVE-2014-5209 Information Exposure vulnerability in multiple products
An Information Disclosure vulnerability exists in NTP 4.2.7p25 private (mode 6/7) messages via a GET_RESTRICT control message, which could let a malicious user obtain sensitive information.
network
low complexity
ntp f5 CWE-200
5.3
2019-12-23 CVE-2019-19151 Improper Privilege Management vulnerability in F5 products
On BIG-IP versions 15.0.0-15.1.0, 14.0.0-14.1.2.3, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, BIG-IQ versions 7.0.0, 6.0.0-6.1.0, and 5.0.0-5.4.0, iWorkflow version 2.3.0, and Enterprise Manager version 3.1.1, authenticated users granted TMOS Shell (tmsh) privileges are able access objects on the file system which would normally be disallowed by tmsh restrictions.
local
low complexity
f5 CWE-269
2.1
2019-12-23 CVE-2019-6688 Unspecified vulnerability in F5 products
On BIG-IP versions 15.0.0-15.0.1.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5 and BIG-IQ versions 6.0.0-6.1.0 and 5.2.0-5.4.0, a user is able to obtain the secret that was being used to encrypt a BIG-IP UCS backup file while sending SNMP query to the BIG-IP or BIG-IQ system, however the user can not access to the UCS files.
network
low complexity
f5
4.0