Skip to content
VulniPulse

F5 Security Advisories & CVEs

453 advisories tracked · F5 SIRT (f5sirt@f5.com CNA) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor F5 CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your F5 device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in F5's recent advisories.

Official source

F5 SIRT (f5sirt@f5.com CNA) via NVD

F5 is its own CVE Numbering Authority. VulniPulse ingests F5's CVEs from the NVD CNA feed (f5sirt@f5.com), each linking to its my.f5.com / support.f5.com security article. Covers BIG-IP (LTM, ASM/Advanced WAF, APM, AFM), BIG-IP Next, BIG-IQ, NGINX / NGINX Plus, F5OS and Distributed Cloud — internet-facing application-delivery and security appliances that are repeatedly mass-exploited (e.g. the CVE-2023-46747 RCE), so a patch-now enterprise audience.

Latest F5 advisories

Medium4.4F5

Medium [CVE-2023-45219] Exposure of Sensitive Information vulnerability exist in an undisclosed BIG-IP TMOS shell (tmsh) command which may

Exposure of Sensitive Information vulnerability exist in an undisclosed BIG-IP TMOS shell (tmsh) command which may allow an authenticated attacker with resource administrator role privileges to view sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-45219
BIG-IP
Oct 10, 2023
Medium5.5F5

Medium [CVE-2023-43485] When TACACS+ audit forwarding is configured on BIG-IP or BIG-IQ system, sharedsecret is logged in plaintext in the audit log

When TACACS+ audit forwarding is configured on BIG-IP or BIG-IQ system, sharedsecret is logged in plaintext in the audit log. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-43485
BIG-IPBIG-IQ
Oct 10, 2023
Medium4.3F5

Medium [CVE-2023-41964] BIG-IP: The BIG-IP and BIG-IQ systems do not encrypt some sensitive information written to Database (DB) variables.

The BIG-IP and BIG-IQ systems do not encrypt some sensitive information written to Database (DB) variables. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-41964
BIG-IPBIG-IQ
Oct 10, 2023
Medium5.5F5

Medium [CVE-2023-41253] When on BIG-IP DNS or BIG-IP LTM enabled with DNS Services License, and a TSIG key is created, it is logged in plaintext in the…

When on BIG-IP DNS or BIG-IP LTM enabled with DNS Services License, and a TSIG key is created, it is logged in plaintext in the audit log. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-41253
BIG-IP
Oct 10, 2023
Medium4.4F5

Medium [CVE-2023-39447] BIG-IP: When BIG-IP APM Guided Configurations are configured, undisclosed sensitive information may be logged in restnoded log.

When BIG-IP APM Guided Configurations are configured, undisclosed sensitive information may be logged in restnoded log. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-39447
BIG-IP
Oct 10, 2023
Medium6.8F5

Medium [CVE-2023-43125] BIG-IP: BIG-IP APM clients may send IP traffic outside of the VPN tunnel.

BIG-IP APM clients may send IP traffic outside of the VPN tunnel. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVE-2023-43125
BIG-IP
Sep 27, 2023
High7.8F5

High [CVE-2023-38418] The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installation process

The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installation process. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-38418
BIG-IP
Aug 2, 2023
High7.5F5

High [CVE-2023-38138] reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which

A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-38138
BIG-IP
Aug 2, 2023
High7.1F5

High [CVE-2023-36858] insufficient verification of data vulnerability exists in BIG-IP Edge Client for Windows and macOS that may

An insufficient verification of data vulnerability exists in BIG-IP Edge Client for Windows and macOS that may allow an attacker to modify its configured server list. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-36858
BIG-IP
Aug 2, 2023
Medium6.0F5

Medium [CVE-2023-3470] Specific F5 BIG-IP platforms with Cavium Nitrox FIPS HSM cards generate a deterministic password for the Crypto User account

Specific F5 BIG-IP platforms with Cavium Nitrox FIPS HSM cards generate a deterministic password for the Crypto User account. The predictable nature of the password allows an authenticated user with TMSH access to the BIG-IP system, or anyone with physical access to the FIPS HSM, the information required to generate the correct password. On vCMP systems, all Guests share the same deterministic password, allowing those with TMSH access on one Guest to access keys of a different Guest. The following BIG-IP hardware platforms are affected: 10350v-F, i5820-DF, i7820-DF, i15820-DF, 5250v-F, 7200v-F, 10200v-F, 6900-F, 8900-F, 11000-F, and 11050-F. The BIG-IP rSeries r5920-DF and r10920-DF are not affected, nor does the issue affect software FIPS implementations or network HSM configurations. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-3470
BIG-IP
Aug 2, 2023
Medium5.4F5

Medium [CVE-2023-38423] cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility

A cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-38423
BIG-IP
Aug 2, 2023
Medium4.3F5

Medium [CVE-2023-38419] authenticated attacker with guest privileges or higher

An authenticated attacker with guest privileges or higher can cause the iControl SOAP process to terminate by sending undisclosed requests. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-38419
Unclassified
Aug 2, 2023
Medium4.4F5

Medium [CVE-2023-36494] F5OS: Audit logs on F5OS-A may contain undisclosed sensitive information.

Audit logs on F5OS-A may contain undisclosed sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-36494
F5OS / Distributed Cloud
Aug 2, 2023
High7.5F5

High [CVE-2023-29163] When UDP profile with idle timeout set to immediate or the value 0 is configured on a virtual server, undisclosed traffic

When UDP profile with idle timeout set to immediate or the value 0 is configured on a virtual server, undisclosed traffic can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-29163
Unclassified
May 3, 2023
High7.2F5

High [CVE-2023-28742] When DNS is provisioned, an authenticated remote command execution vulnerability exists in DNS iQuery mesh.

When DNS is provisioned, an authenticated remote command execution vulnerability exists in DNS iQuery mesh. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-28742
Unclassified
May 3, 2023
High7.1F5

High [CVE-2023-28724] NGINX Management Suite default file permissions are set such that an authenticated attacker

NGINX Management Suite default file permissions are set such that an authenticated attacker may be able to modify sensitive files on NGINX Instance Manager and NGINX API Connectivity Manager. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-28724
NGINX
May 3, 2023
High8.1F5

High [CVE-2023-28656] NGINX Management Suite may

NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned environment. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-28656
NGINX
May 3, 2023
High7.5F5

High [CVE-2023-27378] Multiple reflected cross-site scripting (XSS) vulnerabilities exist in undisclosed pages of the BIG-IP Configuration utility which

Multiple reflected cross-site scripting (XSS) vulnerabilities exist in undisclosed pages of the BIG-IP Configuration utility which allow an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-27378
BIG-IP
May 3, 2023
High7.4F5

High [CVE-2023-24461] improper certificate validation vulnerability exists in the BIG-IP Edge Client for Windows and macOS and may

An improper certificate validation vulnerability exists in the BIG-IP Edge Client for Windows and macOS and may allow an attacker to impersonate a BIG-IP APM system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-24461
BIG-IP
May 3, 2023
Medium5.4F5

Medium [CVE-2023-29240] authenticated attacker granted a Viewer or Auditor role on a BIG-IQ

An authenticated attacker granted a Viewer or Auditor role on a BIG-IQ can upload arbitrary files using an undisclosed iControl REST endpoint. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-29240
BIG-IQ
May 3, 2023

← All vendors