1941
|
- |
|
-
|
-
|
When BIG-IP AFM is provisioned with IPS module enabled and protocol inspection profile is configured on a virtual server or firewall rule or policy, undisclosed traffic can cause an increase in CPU r…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2025-24312
|
2025-02-6 03:15 |
2025-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1942
|
- |
|
-
|
-
|
An insufficient verification of data authenticity vulnerability exists in BIG-IP APM Access Policy endpoint inspection that may allow an attacker to bypass endpoint inspection checks for VPN connecti…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2025-23415
|
2025-02-6 03:15 |
2025-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1943
|
- |
|
-
|
-
|
When users log in through the webUI or API using local authentication, BIG-IP Next Central Manager may log sensitive information in the pgaudit log files.
Note: Software versions which have reache…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2025-23413
|
2025-02-6 03:15 |
2025-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1944
|
- |
|
-
|
-
|
When BIG-IP APM Access Profile is configured on a virtual server, undisclosed request can cause TMM to terminate.
Note: Software versions which have reached End of Technical Support (EoTS) are…
|
CWE-120
Classic Buffer Overflow
|
CVE-2025-23412
|
2025-02-6 03:15 |
2025-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1945
|
- |
|
-
|
-
|
When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a securit…
|
CWE-77
Command Injection
|
CVE-2025-23239
|
2025-02-6 03:15 |
2025-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1946
|
- |
|
-
|
-
|
When BIG-IP PEM Control Plane listener Virtual Server is configured with Diameter Endpoint profile, undisclosed traffic can cause the Virtual Server to stop processing new client connections and an i…
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2025-22891
|
2025-02-6 03:15 |
2025-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1947
|
- |
|
-
|
-
|
When SIP Session and Router ALG profiles are configured on a Message Routing type virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.
Note: Softw…
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2025-22846
|
2025-02-6 03:15 |
2025-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1948
|
- |
|
-
|
-
|
When SNMP v1 or v2c are disabled on the BIG-IP, undisclosed requests can cause an increase in memory resource utilization.
Note: Software versions which have reached End of Technical Support (Eo…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2025-21091
|
2025-02-6 03:15 |
2025-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1949
|
- |
|
-
|
-
|
When Client or Server SSL profiles are configured on a Virtual Server, or DNSSEC signing operations are in use, undisclosed traffic can cause an increase in memory and CPU resource utilization.
…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2025-21087
|
2025-02-6 03:15 |
2025-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1950
|
- |
|
-
|
-
|
When a BIG-IP message routing profile is configured on a virtual server, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Te…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2025-20058
|
2025-02-6 03:15 |
2025-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|