|
208151
|
6.1 |
MEDIUM
Network
|
f5
|
big-ip_access_policy_manager
|
In versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, an undisclosed link on the BIG-IP APM virtual server allows a malicious user to bui…
|
CWE-601
Open Redirect
|
CVE-2020-27729
|
2024-11-21 14:21 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208152
|
7.5 |
HIGH
Network
|
f5
|
big-ip_application_security_manager big-ip_advanced_web_application_firewall
|
On BIG-IP ASM & Advanced WAF versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.3, under certain conditions, Analytics, Visibility, and Reporting daemon (AVRD) may generate a core file and re…
|
NVD-CWE-noinfo
|
CVE-2020-27728
|
2024-11-21 14:21 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208153
|
4.9 |
MEDIUM
Network
|
f5
|
big-ip_local_traffic_manager big-ip_application_acceleration_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_access_policy_manager big-ip_application_security_manager<…
|
On BIG-IP version 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, and 13.1.0-13.1.3.4, when an authenticated administrative user installs RPMs using the iAppsLX REST installer, the BIG-IP system doe…
|
CWE-20
Improper Input Validation
|
CVE-2020-27727
|
2024-11-21 14:21 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208154
|
6.1 |
MEDIUM
Network
|
f5
|
big-ip_access_policy_manager
|
In versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, and 12.1.0-12.1.5.2, a reflected cross-site scripting (XSS) vulnerability exists in the resource information page for aut…
|
CWE-79
Cross-site Scripting
|
CVE-2020-27726
|
2024-11-21 14:21 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208155
|
7.5 |
HIGH
Network
|
f5
|
big-ip_access_policy_manager
|
In versions 14.1.0-14.1.3 and 13.1.0-13.1.3.4, a BIG-IP APM virtual server processing PingAccess requests may lead to a restart of the Traffic Management Microkernel (TMM) process.
|
NVD-CWE-noinfo
|
CVE-2020-27723
|
2024-11-21 14:21 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208156
|
6.5 |
MEDIUM
Network
|
f5
|
big-ip_access_policy_manager
|
In BIG-IP APM versions 15.0.0-15.0.1.3, 14.1.0-14.1.3, and 13.1.0-13.1.3.4, under certain conditions, the VDI plugin does not observe plugin flow-control protocol causing excessive resource consumpti…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-27722
|
2024-11-21 14:21 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208157
|
7.5 |
HIGH
Network
|
f5
|
big-ip_local_traffic_manager big-ip_carrier-grade_nat
|
On BIG-IP LTM/CGNAT version 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, and 13.1.0-13.1.3.5, when processing NAT66 traffic with Port Block Allocation (PBA) mode and SP-DAG enabled, and dag-ipv6-…
|
NVD-CWE-noinfo
|
CVE-2020-27720
|
2024-11-21 14:21 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208158
|
6.1 |
MEDIUM
Network
|
f5
|
big-ip_local_traffic_manager big-ip_application_acceleration_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_access_policy_manager big-ip_application_security_manager<…
|
On BIG-IP 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.3, a cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility.
|
CWE-79
Cross-site Scripting
|
CVE-2020-27719
|
2024-11-21 14:21 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208159
|
7.5 |
HIGH
Network
|
f5
|
big-ip_domain_name_system
|
On BIG-IP DNS 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, and 12.1.0-12.1.5.2, undisclosed series of DNS requests may cause TMM to restart and generate a core file.
|
NVD-CWE-noinfo
|
CVE-2020-27717
|
2024-11-21 14:21 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208160
|
7.5 |
HIGH
Network
|
f5
|
big-ip_access_policy_manager
|
On versions 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.5, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, when a BIG-IP APM virtual server processes traffic of an undisclosed nature, the Traffic Management …
|
NVD-CWE-noinfo
|
CVE-2020-27716
|
2024-11-21 14:21 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|