CVE-2025-41430
- EPSS 0.11%
- Veröffentlicht 15.10.2025 13:55:48
- Zuletzt bearbeitet 21.10.2025 19:49:43
When BIG-IP SSL Orchestrator is enabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2021-23004
- EPSS 0.65%
- Veröffentlicht 31.03.2021 18:15:15
- Zuletzt bearbeitet 21.11.2024 05:51:08
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, Multipath TCP (MPTCP) forwarding flows may be created on standard virtual servers wit...
CVE-2021-23003
- EPSS 0.65%
- Veröffentlicht 31.03.2021 18:15:15
- Zuletzt bearbeitet 21.11.2024 05:51:07
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, the Traffic Management Microkernel (TMM) process may produce a core file when undiscl...
CVE-2021-23001
- EPSS 0.25%
- Veröffentlicht 31.03.2021 18:15:15
- Zuletzt bearbeitet 21.11.2024 05:51:07
On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, the upload functionality in BIG-IP Advanced WAF and BIG-IP ASM allows an authenticated user ...
CVE-2021-23000
- EPSS 0.65%
- Veröffentlicht 31.03.2021 18:15:15
- Zuletzt bearbeitet 21.11.2024 05:51:07
On BIG-IP versions 13.1.3.4-13.1.3.6 and 12.1.5.2, if the tmm.http.rfc.enforcement BigDB key is enabled in a BIG-IP system, or the Bad host header value is checked in the AFM HTTP security profile associated with a virtual server, in rare instances, ...
CVE-2021-22999
- EPSS 0.65%
- Veröffentlicht 31.03.2021 18:15:15
- Zuletzt bearbeitet 21.11.2024 05:51:07
On versions 15.0.x before 15.1.0 and 14.1.x before 14.1.4, the BIG-IP system provides an option to connect HTTP/2 clients to HTTP/1.x servers. When a client is slow to accept responses and it closes a connection prematurely, the BIG-IP system may ind...
CVE-2021-22998
- EPSS 0.63%
- Veröffentlicht 31.03.2021 18:15:15
- Zuletzt bearbeitet 21.11.2024 05:51:05
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, SYN flood protection thresholds are not enforced in secure network address translatio...
CVE-2021-22994
- EPSS 0.32%
- Veröffentlicht 31.03.2021 18:15:14
- Zuletzt bearbeitet 21.11.2024 05:51:05
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, undisclosed endpoints in iControl REST allow for a reflected XSS attack, which could ...
CVE-2021-22991
- EPSS 66.26%
- Veröffentlicht 31.03.2021 18:15:14
- Zuletzt bearbeitet 27.10.2025 17:06:52
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, undisclosed requests to a virtual server may be incorrectly handled by the Traffic Management Microkernel (TM...
CVE-2021-22992
- EPSS 7.78%
- Veröffentlicht 31.03.2021 17:15:13
- Zuletzt bearbeitet 21.11.2024 05:51:05
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, a malicious HTTP response to an Advanced WAF/BIG-IP ASM virtual server with Login Pag...