Known vulnerabilities in BIG-IP 14.1.2.0.11.37-ENG Hotfix - page 3

Software: BIG-IP
Version: 14.1.2.0.11.37-ENG Hotfix
Software CPE: cpe:2.3:h:f5_networks:big-ip:*:*:*:*:*:*:*:*
Total vulnerabilities: 146
Public exploits: 14
Known exploited (KEV): 5
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting BIG-IP version 14.1.2.0.11.37-ENG Hotfix BIG-IP 14.1.2.0.11.37-ENG Hotfix is affected by 146 vulnerabilities: 14 high, 70 medium, 62 low Critical High Medium Low

Vulnerabilities (146)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU64083 - Out-of-bounds read
CVE-2022-28615
CWE-125 Low
No
No
- 08.06.2022 SB2022060817
SB2022060901
SB2022061611
and 41 more
#VU64081 - Out-of-bounds read
CVE-2022-28614
CWE-125 Low
No
No
- 08.06.2022 SB2022060817
SB2022060901
SB2022061611
and 36 more
#VU63181 - Unchecked Return Value
CVE-2021-0155
CWE-252 Low
No
No
- 16.05.2022 SB2022051714
SB2022062301
SB2022081211
and 12 more
#VU63177 - Out-of-bounds write
CVE-2021-33124
CWE-787 Low
No
No
- 16.05.2022 SB2022051714
SB2022062306
SB2022081211
and 13 more
#VU63099 - Uncaught Exception
CVE-2021-0190
CWE-248 Low
No
No
- 12.05.2022 SB2022051714
SB2022062303
SB2022081211
and 13 more
#VU63083 - Improper Access Control
CVE-2021-33123
CWE-284 Low
No
No
- 12.05.2022 SB2022051714
SB2022062305
SB2022081211
and 13 more
#VU63082 - Out-of-bounds write
CVE-2021-0153
CWE-787 Low
No
No
- 12.05.2022 SB2022051714
SB2022062304
SB2022081211
and 13 more
#VU63081 - Improper input validation
CVE-2021-0154
CWE-20 Low
No
No
- 11.05.2022 SB2022051714
SB2022062302
SB2022081211
and 13 more
#VU62910 - Missing Authentication for Critical Function
CVE-2022-1388
CWE-306 High
Public exploit available
Exploited
13.1.5, 14.1.4.6, 15.1.5.1, 16.1.2.2 10.05.2022 SB2022051005
#VU62825 - Improper Access Control
CVE-2022-28859
CWE-284 Medium
No
No
14.1.4.6, 15.1.5.1, 16.1.0 05.05.2022 SB2022050521
#VU62824 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2022-26835
CWE-22 Low
No
No
13.1.5, 14.1.4.6, 15.1.5.1, 16.1.2.2 05.05.2022 SB2022050520
#VU62820 - Improper input validation
CVE-2022-29479
CWE-20 Medium
No
No
13.1.5, 14.1.4.6, 15.1.5.1, 16.1.0 05.05.2022 SB2022050516
#VU62814 - Improper Check for Unusual or Exceptional Conditions
CVE-2022-29473
CWE-754 Medium
No
No
13.1.5, 14.1.4.5, 15.1.5.1 05.05.2022 SB2022050511
#VU56017 - Out-of-bounds write
CVE-2021-22555
CWE-787 Low
Public exploit available
Exploited
- 20.08.2021 SB2021070718
SB2021082206
SB2021083120
and 53 more
#VU55258 - Missing release of memory after effective lifetime
CVE-2020-25704
CWE-401 Low
No
No
- 22.07.2021 SB2020120226
SB2021072251
SB2021072252
and 25 more
#VU15643 - Improper Access Control
CVE-2018-18281
CWE-284 Low
No
No
13.1.5, 14.1.4.6, 14.1.5, 15.1.5.1, 15.1.6, 16.1.2.2, 16.1.3 31.10.2018 SB2018103107
SB2018112105
SB2019080809
and 10 more
#VU13530 - Exposure of sensitive information to an unauthorized actor
CVE-2018-12536
CWE-200 Low
No
No
- 02.07.2018 SB2018070205
SB2022032830
SB2022032831
and 8 more
#VU13529 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2017-7658
CWE-444 Low
No
No
- 02.07.2018 SB2018070205
SB2018082001
SB2020102711
and 17 more
#VU13528 - Exposure of sensitive information to an unauthorized actor
CVE-2017-7657
CWE-200 Low
No
No
- 02.07.2018 SB2018070205
SB2018082001
SB2022040632
and 18 more
#VU13527 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2017-7656
CWE-444 Low
No
No
- 30.06.2018 SB2018070205
SB2018082001
SB2022041923
and 17 more


Showing elements 41 - 60 out of 146