- EPSS 2.38%
- Veröffentlicht 31.03.2021 15:15:15
- Zuletzt bearbeitet 21.11.2024 05:51:04
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, TMUI, also referred to as the Configuration utility, has an authenticated remote comm...
CVE-2021-22977
- EPSS 0.65%
- Veröffentlicht 12.02.2021 20:15:13
- Zuletzt bearbeitet 21.11.2024 05:51:03
On BIG-IP version 16.0.0-16.0.1 and 14.1.2.4-14.1.3, cooperation between malicious HTTP client code and a malicious server may cause TMM to restart and generate a core file. Note: Software versions which have reached End of Software Development (EoSD...
CVE-2021-22978
- EPSS 0.82%
- Veröffentlicht 12.02.2021 20:15:13
- Zuletzt bearbeitet 21.11.2024 05:51:03
On BIG-IP version 16.0.x before 16.0.1, 15.1.x before 15.1.1, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.5, and all 12.1.x and 11.6.x versions, undisclosed endpoints in iControl REST allow for a reflected XSS attack, which could lead to a complete ...
CVE-2021-22979
- EPSS 0.32%
- Veröffentlicht 12.02.2021 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:51:03
On BIG-IP version 16.0.x before 16.0.1, 15.1.x before 15.1.1, 14.1.x before 14.1.2.8, 13.1.x before 13.1.3.5, and all 12.1.x versions, a reflected Cross-Site Scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration util...
CVE-2021-22981
- EPSS 0.23%
- Veröffentlicht 12.02.2021 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:51:03
On all versions of BIG-IP 12.1.x and 11.6.x, the original TLS protocol includes a weakness in the master secret negotiation that is mitigated by the Extended Master Secret (EMS) extension defined in RFC 7627. TLS connections that do not use EMS are v...
CVE-2021-22982
- EPSS 0.43%
- Veröffentlicht 12.02.2021 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:51:03
On BIG-IP DNS and GTM version 13.1.x before 13.1.0.4, and all versions of 12.1.x and 11.6.x, big3d does not securely handle and parse certain payloads resulting in a buffer overflow. Note: Software versions which have reached End of Software Developm...
CVE-2021-22973
- EPSS 0.65%
- Veröffentlicht 12.02.2021 17:15:14
- Zuletzt bearbeitet 21.11.2024 05:51:02
On BIG-IP version 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.5, and all 12.1.x versions, JSON parser function does not protect against out-of-bounds memory accesses or writes. Note: Software versions wh...
CVE-2021-22974
- EPSS 0.33%
- Veröffentlicht 12.02.2021 17:15:14
- Zuletzt bearbeitet 21.11.2024 05:51:02
On BIG-IP version 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, and 13.1.x before 13.1.3.6 and all versions of BIG-IQ 7.x and 6.x, an authenticated attacker with access to iControl REST over the control plane may be able to ta...
CVE-2021-22975
- EPSS 0.65%
- Veröffentlicht 12.02.2021 17:15:14
- Zuletzt bearbeitet 21.11.2024 05:51:03
On BIG-IP version 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, and 14.1.x before 14.1.3.1, under some circumstances, Traffic Management Microkernel (TMM) may restart on the BIG-IP system while passing large bursts of traffic. Note: Software versio...
CVE-2020-27719
- EPSS 0.47%
- Veröffentlicht 24.12.2020 16:15:15
- Zuletzt bearbeitet 21.11.2024 05:21:41
On BIG-IP 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.3, a cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility.