CVE-2021-23027
- EPSS 0.39%
- Veröffentlicht 14.09.2021 22:15:07
- Zuletzt bearbeitet 21.11.2024 05:51:10
On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, and 14.1.x before 14.1.4.3, a DOM based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to execute JavaScrip...
CVE-2021-23025
- EPSS 1.12%
- Veröffentlicht 14.09.2021 21:15:07
- Zuletzt bearbeitet 21.11.2024 05:51:10
On version 15.1.x before 15.1.0.5, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.5, and all versions of 12.1.x and 11.6.x, an authenticated remote command execution vulnerability exists in the BIG-IP Configuration utility. Note: Software versions whic...
CVE-2021-23032
- EPSS 0.89%
- Veröffentlicht 14.09.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:51:11
On version 16.x before 16.1.0, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x and 12.1.x, when a BIG-IP DNS system is configured with non-default Wide IP and pool settings, undisclosed DNS responses can cause the Traffic M...
CVE-2021-23034
- EPSS 0.92%
- Veröffentlicht 14.09.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:51:11
On BIG-IP version 16.x before 16.1.0 and 15.1.x before 15.1.3.1, when a DNS profile using a DNS cache resolver is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) process to terminate. Note: Soft...
CVE-2021-23035
- EPSS 0.86%
- Veröffentlicht 14.09.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:51:11
On BIG-IP 14.1.x before 14.1.4.4, when an HTTP profile is configured on a virtual server, after a specific sequence of packets, chunked responses can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reac...
CVE-2021-23037
- EPSS 0.71%
- Veröffentlicht 14.09.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:51:11
On all versions of 16.1.x, 16.0.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x, a reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to execute JavaScript in the...
- EPSS 0.33%
- Veröffentlicht 14.09.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:51:11
On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x, a stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility...
CVE-2021-23039
- EPSS 0.57%
- Veröffentlicht 14.09.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:51:12
On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.2.8, and all versions of 13.1.x and 12.1.x, when IPSec is configured on a BIG-IP system, undisclosed requests from an authorized remote (IPSec) peer, which already has a nego...
CVE-2021-23045
- EPSS 0.65%
- Veröffentlicht 14.09.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 05:51:12
On BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, 13.1.x before 13.1.4.1, and all versions of 12.1.x, when an SCTP profile with multiple paths is configured on a virtual server, undisclosed requests can cause t...
CVE-2021-23044
- EPSS 0.89%
- Veröffentlicht 14.09.2021 16:15:09
- Zuletzt bearbeitet 21.11.2024 05:51:12
On BIG-IP version 16.x before 16.1.0, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x and 11.6.x, when the Intel QuickAssist Technology (QAT) compression driver is used on affected BIG-IP hardware an...