CVE-2025-60016
- EPSS 0.07%
- Veröffentlicht 15.10.2025 13:55:44
- Zuletzt bearbeitet 22.10.2025 21:06:10
When Diffie-Hellman (DH) group Elliptic Curve Cryptography (ECC) Brainpool curves are configured in an SSL profile's Cipher Rule or Cipher Group, and that profile is applied to a virtual server, undisclosed traffic can cause the Traffic Management Mi...
CVE-2025-59478
- EPSS 0.07%
- Veröffentlicht 15.10.2025 13:55:43
- Zuletzt bearbeitet 22.10.2025 21:00:40
When a BIG-IP AFM denial-of-service (DoS) protection profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) process to terminate. Note: Software versions which have reached End of Technical...
CVE-2025-58474
- EPSS 0.07%
- Veröffentlicht 15.10.2025 13:55:43
- Zuletzt bearbeitet 22.10.2025 21:00:17
When BIG-IP Advanced WAF is configured on a virtual server with Server-Side Request Forgery (SSRF) protection or when an NGINX server is configured with App Protect Bot Defense, undisclosed requests can disrupt new client requests. Note: Software ve...
CVE-2025-47148
- EPSS 0.07%
- Veröffentlicht 15.10.2025 13:55:42
- Zuletzt bearbeitet 21.10.2025 18:53:54
When the BIG-IP system is configured as both a Security Assertion Markup Language (SAML) service provider (SP) and Identity Provider (IdP), with single logout (SLO) enabled on an access policy, undisclosed requests can cause an increase in memory res...
CVE-2025-59269
- EPSS 0.03%
- Veröffentlicht 15.10.2025 13:55:42
- Zuletzt bearbeitet 21.10.2025 19:33:38
A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reache...
CVE-2025-59268
- EPSS 0.05%
- Veröffentlicht 15.10.2025 13:55:42
- Zuletzt bearbeitet 21.10.2025 19:33:09
On the BIG-IP system, undisclosed endpoints that contain static non-sensitive information are accessible to an unauthenticated remote attacker through the Configuration utility. Note: Software versions which have reached End of Technical Support (Eo...
CVE-2025-53474
- EPSS 0.07%
- Veröffentlicht 15.10.2025 13:55:41
- Zuletzt bearbeitet 21.10.2025 19:49:57
When an iRule using an ILX::call command is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evalu...
CVE-2025-54500
- EPSS 0.09%
- Veröffentlicht 13.08.2025 14:46:55
- Zuletzt bearbeitet 04.02.2026 17:47:28
An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit (HTTP/2 MadeYouReset Attack). Note: Software versions which have reached End of Technical Su...
CVE-2025-46405
- EPSS 0.09%
- Veröffentlicht 13.08.2025 14:46:54
- Zuletzt bearbeitet 21.10.2025 18:29:49
When Network Access is configured on a BIG-IP APM virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2025-48500
- EPSS 0.01%
- Veröffentlicht 13.08.2025 14:46:54
- Zuletzt bearbeitet 21.10.2025 18:29:37
A missing file integrity check vulnerability exists on MacOS F5 VPN browser client installer that may allow a local, authenticated attacker with access to the local file system to replace it with a malicious package installer. Note: Software version...