Vulnerabilities > F5 > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-09-14 CVE-2021-23046 Information Exposure Through Log Files vulnerability in F5 products
On all versions of Guided Configuration before 8.0.0, when a configuration that contains secure properties is created and deployed from Access Guided Configuration (AGC), secure properties are logged in restnoded logs.
network
low complexity
f5 CWE-532
4.9
2021-09-14 CVE-2021-23041 Cross-site Scripting vulnerability in F5 products
On BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x, a DOM based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to execute JavaScript in the context of the current logged-in user.
network
low complexity
f5 CWE-79
6.1
2021-09-14 CVE-2021-23047 Resource Exhaustion vulnerability in F5 Big-Ip Access Policy Manager
On version 16.x before 16.1.0, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, and all versions of 13.1.x, 12.1.x and 11.6.x, when BIG-IP APM performs Online Certificate Status Protocol (OCSP) verification of a certificate that contains Authority Information Access (AIA), undisclosed requests may cause an increase in memory use.
network
low complexity
f5 CWE-400
5.3
2021-09-14 CVE-2021-23052 Open Redirect vulnerability in F5 Big-Ip Access Policy Manager
On version 14.1.x before 14.1.4.4 and all versions of 13.1.x, an open redirect vulnerability exists on virtual servers enabled with a BIG-IP APM access policy.
network
low complexity
f5 CWE-601
6.1
2021-09-14 CVE-2021-23053 Allocation of Resources Without Limits or Throttling vulnerability in F5 products
On version 15.1.x before 15.1.3, 14.1.x before 14.1.3.1, and 13.1.x before 13.1.3.6, when the brute force protection feature of BIG-IP Advanced WAF or BIG-IP ASM is enabled on a virtual server and the virtual server is under brute force attack, the MySQL database may run out of disk space due to lack of row limit on undisclosed tables in the MYSQL database.
network
low complexity
f5 CWE-770
5.3
2021-06-01 CVE-2021-23020 Use of Insufficiently Random Values vulnerability in F5 Nginx Controller
The NAAS 3.x before 3.10.0 API keys were generated using an insecure pseudo-random string and hashing algorithm which could lead to predictable keys.
local
low complexity
f5 CWE-330
5.5
2021-06-01 CVE-2021-23021 Incorrect Permission Assignment for Critical Resource vulnerability in F5 Nginx Controller
The Nginx Controller 3.x before 3.7.0 agent configuration file /etc/controller-agent/agent.conf is world readable with current permission bits set to 644.
local
low complexity
f5 CWE-732
5.5
2021-05-10 CVE-2021-23016 Unspecified vulnerability in F5 Big-Ip Access Policy Manager
On BIG-IP APM versions 15.1.x before 15.1.3, 14.1.x before 14.1.4.1, 13.1.x before 13.1.4, and all versions of 16.0.x, 12.1.x, and 11.6.x, an attacker may be able to bypass APM's internal restrictions and retrieve static content that is hosted within APM by sending specifically crafted requests to an APM Virtual Server.
network
low complexity
f5
5.3
2021-03-31 CVE-2021-23007 Unspecified vulnerability in F5 products
On BIG-IP versions 14.1.4 and 16.0.1.1, when the Traffic Management Microkernel (TMM) process handles certain undisclosed traffic, it may start dropping all fragmented IP traffic.
network
low complexity
f5
5.3
2021-03-31 CVE-2021-23006 Cross-site Scripting vulnerability in F5 Big-Iq Centralized Management
On all 7.x and 6.x versions (fixed in 8.0.0), undisclosed BIG-IQ pages have a reflected cross-site scripting vulnerability.
network
low complexity
f5 CWE-79
6.1