|
195991
|
9.6 |
CRITICAL
Network
|
f5
|
big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_acceleration_manager big-ip_application_security_manager big-ip_domain_name_system …
|
On all versions of 16.1.x, 16.0.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x, a reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility t…
|
CWE-79
Cross-site Scripting
|
CVE-2021-23037
|
2024-11-21 14:51 |
2021-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195992
|
7.5 |
HIGH
Network
|
f5
|
big-ip_policy_enforcement_manager big-ip_local_traffic_manager big-ip_link_controller big-ip_global_traffic_manager big-ip_fraud_protection_service big-ip_domain_name_system big-ip_…
|
On BIG-IP 14.1.x before 14.1.4.4, when an HTTP profile is configured on a virtual server, after a specific sequence of packets, chunked responses can cause the Traffic Management Microkernel (TMM) to…
|
NVD-CWE-noinfo
|
CVE-2021-23035
|
2024-11-21 14:51 |
2021-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195993
|
7.5 |
HIGH
Network
|
f5
|
big-ip_advanced_web_application_firewall big-ip_application_security_manager
|
On BIG-IP Advanced WAF and BIG-IP ASM version 16.x before 16.1.0x, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, 13.1.x before 13.1.4.1, and all versions of 12.1.x, when a WebSocket profile is conf…
|
NVD-CWE-noinfo
|
CVE-2021-23033
|
2024-11-21 14:51 |
2021-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195994
|
7.5 |
HIGH
Network
|
f5
|
big-ip_domain_name_system
|
On version 16.x before 16.1.0, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x and 12.1.x, when a BIG-IP DNS system is configured with non-default Wide IP and pool settings…
|
NVD-CWE-noinfo
|
CVE-2021-23032
|
2024-11-21 14:51 |
2021-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195995
|
7.5 |
HIGH
Network
|
f5
|
big-ip_global_traffic_manager big-ip_link_controller big-ip_local_traffic_manager big-ip_policy_enforcement_manager big-ip_access_policy_manager big-ip_advanced_firewall_manager big…
|
On BIG-IP version 16.x before 16.1.0 and 15.1.x before 15.1.3.1, when a DNS profile using a DNS cache resolver is configured on a virtual server, undisclosed requests can cause the Traffic Management…
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2021-23034
|
2024-11-21 14:51 |
2021-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195996
|
7.5 |
HIGH
Network
|
f5
|
big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_advanced_web_application_firewall big-ip_analytics big-ip_ddos_hybrid_defender big-ip_domain_name_system big-ip_…
|
On BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, 13.1.x before 13.1.4.1, and all versions of 12.1.x, when an SCTP profile with multiple paths is configured on…
|
NVD-CWE-noinfo
|
CVE-2021-23045
|
2024-11-21 14:51 |
2021-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195997
|
7.5 |
HIGH
Network
|
f5
|
big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_acceleration_manager big-ip_application_security_manager big-ip_domain_name_system …
|
On BIG-IP version 16.x before 16.1.0, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x and 11.6.x, when the Intel QuickAssist Technology (QAT) compre…
|
NVD-CWE-noinfo
|
CVE-2021-23044
|
2024-11-21 14:51 |
2021-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195998
|
4.9 |
MEDIUM
Network
|
f5
|
big-ip_access_policy_manager big-ip_guided_configuration
|
On all versions of Guided Configuration before 8.0.0, when a configuration that contains secure properties is created and deployed from Access Guided Configuration (AGC), secure properties are logged…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2021-23046
|
2024-11-21 14:51 |
2021-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195999
|
8.8 |
HIGH
Network
|
f5
|
big-ip_advanced_firewall_manager
|
On BIG-IP AFM version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x, a SQL injection vulnerability exists in an undisclosed …
|
CWE-89
SQL Injection
|
CVE-2021-23040
|
2024-11-21 14:51 |
2021-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196000
|
5.3 |
MEDIUM
Network
|
f5
|
big-ip_access_policy_manager
|
On version 16.x before 16.1.0, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, and all versions of 13.1.x, 12.1.x and 11.6.x, when BIG-IP APM performs Online Certificate Status Protocol (OCSP) verifi…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2021-23047
|
2024-11-21 14:51 |
2021-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|