Known vulnerabilities in BIG-IQ Centralized Management 7.0.0

Version: 7.0.0
Software CPE: cpe:2.3:a:f5_networks:big-iq:*:*:*:*:*:*:*:*
Total vulnerabilities: 67
Public exploits: 13
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting BIG-IQ Centralized Management version 7.0.0 BIG-IQ Centralized Management 7.0.0 is affected by 67 vulnerabilities: 6 high, 30 medium, 31 low Critical High Medium Low

Vulnerabilities (67)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU66089 - Insufficient Session Expiration
CVE-2022-35728
CWE-613 Medium
No
No
8.2.0 04.08.2022 SB2022080411
#VU64396 - Observable discrepancy
CVE-2022-23823
CWE-203 Medium
No
No
- 15.06.2022 SB2022061516
SB20250227198
SB20250227199
and 1 more
#VU64378 - Observable discrepancy
CVE-2022-24436
CWE-203 Medium
No
No
- 14.06.2022 SB2022061501
SB20250227202
SB20250227203
and 1 more
#VU62820 - Improper input validation
CVE-2022-29479
CWE-20 Medium
No
No
- 05.05.2022 SB2022050516
#VU61286 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-22720
CWE-444 Medium
No
No
- 14.03.2022 SB2022031416
SB2022031504
SB2022031724
and 56 more
#VU61246 - Use After Free
CVE-2021-4083
CWE-416 Low
No
No
- 10.03.2022 SB2022031029
SB2022031033
SB2022031034
and 55 more
#VU59871 - Resource exhaustion
CVE-2022-23023
CWE-400 Low
No
No
- 20.01.2022 SB2022012006
SB2022012007
#VU56064 - Out-of-bounds read
CVE-2021-3712
CWE-125 Medium
No
No
- 24.08.2021 SB2021082414
SB2021082508
SB2021082510
and 142 more
#VU56017 - Out-of-bounds write
CVE-2021-22555
CWE-787 Low
Public exploit available
Exploited
- 20.08.2021 SB2021070718
SB2021082206
SB2021083120
and 53 more
#VU55258 - Missing release of memory after effective lifetime
CVE-2020-25704
CWE-401 Low
No
No
- 22.07.2021 SB2020120226
SB2021072251
SB2021072252
and 25 more
#VU51836 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2021-21295
CWE-444 Medium
No
No
- 01.04.2021 SB2021040115
SB2021040626
SB2021050706
and 26 more
#VU48942 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2020-27216
CWE-362 Low
No
No
- 23.10.2020 SB2020121307
SB2020121308
SB2021012011
and 27 more
#VU29032 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-7676
CWE-79 Low
No
No
- 16.06.2020 SB2020061604
SB2021072628
SB2021072629
and 19 more
#VU29015 - Integer overflow
CVE-2020-10878
CWE-190 High
No
No
- 15.06.2020 SB2020061513
SB2020061514
SB2020062302
and 49 more
#VU21091 - Out-of-bounds read
CVE-2019-15903
CWE-125 Medium
Public exploit available
No
- 12.09.2019 SB2019091209
SB2019091210
SB2019091701
and 61 more
#VU15643 - Improper Access Control
CVE-2018-18281
CWE-284 Low
No
No
- 31.10.2018 SB2018103107
SB2018112105
SB2019080809
and 10 more
#VU13530 - Exposure of sensitive information to an unauthorized actor
CVE-2018-12536
CWE-200 Low
No
No
- 02.07.2018 SB2018070205
SB2022032830
SB2022032831
and 8 more
#VU13529 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2017-7658
CWE-444 Low
No
No
- 02.07.2018 SB2018070205
SB2018082001
SB2020102711
and 17 more
#VU13528 - Exposure of sensitive information to an unauthorized actor
CVE-2017-7657
CWE-200 Low
No
No
- 02.07.2018 SB2018070205
SB2018082001
SB2022040632
and 18 more
#VU13527 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2017-7656
CWE-444 Low
No
No
- 30.06.2018 SB2018070205
SB2018082001
SB2022041923
and 17 more


Showing elements 1 - 20 out of 67