CVE-2022-27182
- EPSS 0.87%
- Published 05.05.2022 17:15:12
- Last modified 21.11.2024 06:55:21
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, and 14.1.x versions prior to 14.1.4.6, when BIG-IP packet filters are enabled and a virtual server is configured with the type set to Reject, undisclosed requests can ...
CVE-2022-27189
- EPSS 0.89%
- Published 05.05.2022 17:15:12
- Last modified 21.11.2024 06:55:22
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, when an Internet Content Adaptation Protocol (ICAP) profile ...
CVE-2022-25946
- EPSS 0.13%
- Published 05.05.2022 17:15:11
- Last modified 21.11.2024 06:53:15
On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP Advanced WAF, ASM, and ASM, and F5 BIG-IP Guided Configuration (GC) all versions prior to 9.0, when running in Appliance mode, an authenticated attacker with Administr...
CVE-2022-26071
- EPSS 1.48%
- Published 05.05.2022 17:15:11
- Last modified 21.11.2024 06:53:22
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, a flaw in the way reply ICMP packets are limited in the Traf...
CVE-2022-26130
- EPSS 0.45%
- Published 05.05.2022 17:15:11
- Last modified 21.11.2024 06:53:29
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, when an Active mode-enabled FTP profile is configured on a virtual server, undisclosed traffic ...
CVE-2022-26340
- EPSS 0.11%
- Published 05.05.2022 17:15:11
- Last modified 21.11.2024 06:53:46
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, and F5 BIG-IQ Centralized Management all versions of 8.x and...
CVE-2022-26370
- EPSS 0.67%
- Published 05.05.2022 17:15:11
- Last modified 21.11.2024 06:53:51
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5, and 14.1.x versions prior to 14.1.4.6, when a Session Initiation Protocol (SIP) message routing framework (MRF) application layer gateway (ALG) profile is configured on ...
CVE-2022-26372
- EPSS 0.89%
- Published 05.05.2022 17:15:11
- Last modified 21.11.2024 06:53:51
On F5 BIG-IP 15.1.x versions prior to 15.1.0.2, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, when a DNS listener is configured on a virtual server with DNS queueing (default), undisclosed ...
CVE-2022-1388
- EPSS 94.46%
- Published 05.05.2022 17:15:10
- Last modified 02.04.2025 18:17:58
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. N...
CVE-2022-1389
- EPSS 0.09%
- Published 05.05.2022 17:15:10
- Last modified 21.11.2024 06:40:37
On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP (fixed in 17.0.0), a cross-site request forgery (CSRF) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility. This vulnerability allows an at...