Vulnerabilities > F5 > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-10-19 CVE-2022-41813 Improper Input Validation vulnerability in F5 products
In versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, when BIG-IP is provisioned with PEM or AFM module, an undisclosed input can cause Traffic Management Microkernel (TMM) to terminate.
network
low complexity
f5 CWE-20
6.5
2022-09-15 CVE-2022-38890 Out-of-bounds Read vulnerability in F5 NJS 0.7.7
Nginx NJS v0.7.7 was discovered to contain a segmentation violation via njs_utf8_next at src/njs_utf8.h
local
low complexity
f5 CWE-125
5.5
2022-08-04 CVE-2022-30535 Improper Input Validation vulnerability in F5 Nginx Ingress Controller
In versions 2.x before 2.3.0 and all versions of 1.x, An attacker authorized to create or update ingress objects can obtain the secrets available to the NGINX Ingress Controller.
network
low complexity
f5 CWE-20
6.5
2022-08-04 CVE-2022-33947 Deserialization of Untrusted Data vulnerability in F5 Big-Ip Domain Name System
In BIG-IP Versions 16.1.x before 16.1.3, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, a vulnerability exists in undisclosed pages of the BIG-IP DNS Traffic Management User Interface (TMUI) that allows an authenticated attacker with at least operator role privileges to cause the Tomcat process to restart and perform unauthorized DNS requests and operations through undisclosed requests.
network
low complexity
f5 CWE-502
6.5
2022-08-04 CVE-2022-33962 Improper Privilege Management vulnerability in F5 products
In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, certain iRules commands may allow an attacker to bypass the access control restrictions for a self IP address, regardless of the port lockdown settings.
local
low complexity
f5 CWE-269
6.7
2022-08-04 CVE-2022-33968 Out-of-bounds Read vulnerability in F5 products
In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, when an LTM monitor or APM SSO is configured on a virtual server, and NTLM challenge-response is in use, undisclosed traffic can cause a buffer over-read.
network
low complexity
f5 CWE-125
4.9
2022-08-04 CVE-2022-34851 Improper Input Validation vulnerability in F5 products
In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, and BIG-IQ Centralized Management all versions of 8.x, an authenticated attacker may cause iControl SOAP to become unavailable through undisclosed requests.
network
low complexity
f5 CWE-20
6.5
2022-08-04 CVE-2022-35241 Resource Exhaustion vulnerability in F5 Nginx Instance Manager
In versions 2.x before 2.3.1 and all versions of 1.x, when NGINX Instance Manager is in use, undisclosed requests can cause an increase in disk resource utilization.
network
low complexity
f5 CWE-400
6.5
2022-08-04 CVE-2022-35272 Improper Resource Shutdown or Release vulnerability in F5 products
In BIG-IP Versions 17.0.x before 17.0.0.1 and 16.1.x before 16.1.3.1, when source-port preserve-strict is configured on an HTTP Message Routing Framework (MRF) virtual server, undisclosed traffic may cause the Traffic Management Microkernel (TMM) to produce a core file and the connection to terminate.
local
low complexity
f5 CWE-404
5.5
2022-06-21 CVE-2022-31306 Use After Free vulnerability in F5 NJS 0.7.2
Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_array_convert_to_slow_array at src/njs_array.c.
local
low complexity
f5 CWE-416
5.5