Vulnerabilities > F5 > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-08-26 CVE-2020-5917 Inadequate Encryption Strength vulnerability in F5 products
In BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2 and BIG-IQ versions 5.2.0-7.0.0, the host OpenSSH servers utilize keys of less than 2048 bits which are no longer considered secure.
network
high complexity
f5 CWE-326
5.9
2020-08-26 CVE-2020-5916 Improper Privilege Management vulnerability in F5 products
In BIG-IP versions 15.1.0-15.1.0.4 and 15.0.0-15.0.1.3 the Certificate Administrator user role and higher privileged roles can perform arbitrary file reads outside of the web root directory.
network
low complexity
f5 CWE-269
6.8
2020-08-26 CVE-2020-5915 Cross-site Scripting vulnerability in F5 products
In BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, an undisclosed TMUI page contains a vulnerability which allows a stored XSS when BIG-IP systems are setup in a device trust.
network
low complexity
f5 CWE-79
6.1
2020-08-13 CVE-2020-24349 Use After Free vulnerability in F5 NJS
njs through 0.4.3, used in NGINX, allows control-flow hijack in njs_value_property in njs_value.c.
local
low complexity
f5 CWE-416
5.5
2020-08-13 CVE-2020-24348 Out-of-bounds Read vulnerability in F5 NJS
njs through 0.4.3, used in NGINX, has an out-of-bounds read in njs_json_stringify_iterator in njs_json.c.
local
low complexity
f5 CWE-125
5.5
2020-08-13 CVE-2020-24347 Out-of-bounds Read vulnerability in F5 NJS
njs through 0.4.3, used in NGINX, has an out-of-bounds read in njs_lvlhsh_level_find in njs_lvlhsh.c.
local
low complexity
f5 CWE-125
5.5
2020-07-02 CVE-2020-5909 Improper Certificate Validation vulnerability in F5 Nginx Controller
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, when users run the command displayed in NGINX Controller user interface (UI) to fetch the agent installer, the server TLS certificate is not verified.
network
low complexity
f5 CWE-295
5.4
2020-07-01 CVE-2020-5908 Information Exposure Through Log Files vulnerability in F5 Big-Ip Access Policy Manager
In versions bundled with BIG-IP APM 12.1.0-12.1.5 and 11.6.1-11.6.5.2, Edge Client for Linux exposes full session ID in the local log files.
local
low complexity
f5 CWE-532
5.5
2020-07-01 CVE-2020-5905 Cross-site Scripting vulnerability in F5 products
In version 11.6.1-11.6.5.2 of the BIG-IP system Configuration utility Network > WCCP page, the system does not sanitize all user-provided data before display.
network
low complexity
f5 CWE-79
4.3
2020-07-01 CVE-2020-5903 Cross-site Scripting vulnerability in F5 products
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, a Cross-Site Scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility.
network
low complexity
f5 CWE-79
6.1