CVE-2026-41959
- EPSS 0.04%
- Veröffentlicht 13.05.2026 14:12:41
- Zuletzt bearbeitet 13.05.2026 16:27:11
Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) network diagnostics commands and in BIG-IP iControl REST. These vulnerabilities may allow an authenticated attacker to view the network status of destination...
CVE-2026-42406
- EPSS 0.03%
- Veröffentlicht 13.05.2026 14:12:41
- Zuletzt bearbeitet 13.05.2026 16:27:11
A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands. Note: Software versions which...
CVE-2026-32643
- EPSS 0.03%
- Veröffentlicht 13.05.2026 14:12:40
- Zuletzt bearbeitet 13.05.2026 16:27:11
A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands. Note: Software versions which ha...
CVE-2026-42937
- EPSS 0.04%
- Veröffentlicht 13.05.2026 14:12:40
- Zuletzt bearbeitet 13.05.2026 16:27:11
Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) arp and ndp commands, and in BIG-IP iControl REST. These vulnerabilities may allow an authenticated attacker to view adjacent network information. Note: ...
CVE-2026-40698
- EPSS 0.05%
- Veröffentlicht 13.05.2026 14:12:36
- Zuletzt bearbeitet 13.05.2026 16:27:11
A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can create SNMP configuration objects through iControl REST or the TMOS shell (tmsh) resulting in priv...
CVE-2026-20916
- EPSS 0.07%
- Veröffentlicht 13.05.2026 14:12:31
- Zuletzt bearbeitet 13.05.2026 16:27:11
An authenticated iControl REST user with low privileges can create or modify arbitrary files through an undisclosed iControl REST endpoint on the BIG-IQ system. Note: Software versions which have reached End of Technical Support (EoTS) are not evalu...
CVE-2026-41957
- EPSS 0.55%
- Veröffentlicht 13.05.2026 14:12:30
- Zuletzt bearbeitet 13.05.2026 16:27:11
An authenticated remote code execution vulnerability through undisclosed vectors exists in the BIG-IP and BIG-IQ Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2026-41219
- EPSS 0.06%
- Veröffentlicht 13.05.2026 14:12:28
- Zuletzt bearbeitet 13.05.2026 16:27:11
An improper sanitization vulnerability exists in the BIG-IP QKView utility that allows a low-privileged attacker to read sensitive information from a QKView file. Note: Software versions which have reached End of Technical Support (EoTS) are not ...
CVE-2026-41954
- EPSS 0.05%
- Veröffentlicht 13.05.2026 14:12:27
- Zuletzt bearbeitet 13.05.2026 16:27:11
Sensitive information disclosure vulnerability exists in the undisclosed iControl REST endpoint and TMOS Shell (tmsh) command which may allow an authenticated attacker with resource administrator role privileges to view sensitive information. Note: ...
CVE-2024-47139
- EPSS 0.76%
- Veröffentlicht 16.10.2024 15:15:16
- Zuletzt bearbeitet 06.08.2025 15:02:44
A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IQ Configuration utility that allows an attacker with the Administrator role to run JavaScript in the context of the currently logged-in user. Note: Softw...