CVE-2022-23030
- EPSS 0.59%
- Veröffentlicht 25.01.2022 20:15:09
- Zuletzt bearbeitet 21.11.2024 06:47:50
On version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versions of 13.1.x, when the BIG-IP Virtual Edition (VE) uses the ixlv driver (which is used in SR-IOV mode and requires Intel X710/XL710/XXV710 family of networ...
CVE-2002-20001
- EPSS 14.68%
- Veröffentlicht 11.11.2021 19:15:07
- Zuletzt bearbeitet 22.08.2025 10:33:16
The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ate...
CVE-2021-23026
- EPSS 0.3%
- Veröffentlicht 14.09.2021 22:15:07
- Zuletzt bearbeitet 21.11.2024 05:51:10
BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x and 11.6.x and all versions of BIG-IQ 8.x, 7.x, and 6.x are vulnerable to cross-site request forgery (CSRF) attack...
CVE-2021-23027
- EPSS 0.39%
- Veröffentlicht 14.09.2021 22:15:07
- Zuletzt bearbeitet 21.11.2024 05:51:10
On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, and 14.1.x before 14.1.4.3, a DOM based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to execute JavaScrip...
CVE-2021-23025
- EPSS 1.12%
- Veröffentlicht 14.09.2021 21:15:07
- Zuletzt bearbeitet 21.11.2024 05:51:10
On version 15.1.x before 15.1.0.5, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.5, and all versions of 12.1.x and 11.6.x, an authenticated remote command execution vulnerability exists in the BIG-IP Configuration utility. Note: Software versions whic...
CVE-2021-23034
- EPSS 0.92%
- Veröffentlicht 14.09.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:51:11
On BIG-IP version 16.x before 16.1.0 and 15.1.x before 15.1.3.1, when a DNS profile using a DNS cache resolver is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) process to terminate. Note: Soft...
CVE-2021-23035
- EPSS 0.86%
- Veröffentlicht 14.09.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:51:11
On BIG-IP 14.1.x before 14.1.4.4, when an HTTP profile is configured on a virtual server, after a specific sequence of packets, chunked responses can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reac...
CVE-2021-23037
- EPSS 0.71%
- Veröffentlicht 14.09.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:51:11
On all versions of 16.1.x, 16.0.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x, a reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to execute JavaScript in the...
- EPSS 0.33%
- Veröffentlicht 14.09.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:51:11
On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x, a stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility...
CVE-2021-23039
- EPSS 0.57%
- Veröffentlicht 14.09.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:51:12
On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.2.8, and all versions of 13.1.x and 12.1.x, when IPSec is configured on a BIG-IP system, undisclosed requests from an authorized remote (IPSec) peer, which already has a nego...