Known vulnerabilities in BIG-IP ASM
Vendor:
F5 Networks
Software:
BIG-IP ASM
Software CPE:
cpe:2.3:h:f5_networks:big-ip_asm:*:*:*:*:*:*:*:*
Website:
https://f5.com/
Total vulnerabilities:
171
Public exploits:
14
Known exploited (KEV):
3
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
12.1.3.3
13.1.3.3
13.1.1.4
13.1.1.3
13.1.1.2
13.1.1.1
13.1.0.7
13.1.0.5
14.1.2.2
15.1.0.3
17.5.0
17.1.1
17.1.0
15.1.10.7
15.1.10.5
15.1.10.4
15.1.10.3
15.1.10.2
15.1.10.1
15.1.10.0
17.5.1
15.1.10.8
17.1.3
15.1.10.6.0.11.6
16.1.5
17.1.2
12.1.4.1
14.1.4.2
17.0.0.1
16.1.3.2
16.1.3.1
16.1.3
14.1.5.2
14.1.5.1
14.1.5
14.1.5.3
15.1.8
16.1.3.3
17.0.0.2
17.0.0
14.1.4.5
15.1.4.1
16.1.2
14.1.4.4
15.1.4
16.1.1
14.1.4.1
12.1.6
16.1.0
13.1.4.1
14.1.4.3
15.1.3.1
16.0.1.2
13.1.4
15.1.3
11.6.5.3
12.1.5.3
14.1.4
13.1.3.6
15.1.2.1
16.0.1.1
14.1.3.1
14.1.2.8
13.1.3.5
14.1.3
16.0.1
15.1.2
15.1.1
13.0.0 HF3
12.1.2 HF2
11.6.2 HF1
15.1.0.5
14.1.2.7
16.0.0
14.1.2-0.89.37
14.1.2.5
15.0.1.4
15.1.0.4
14.1.2.6
13.1.3.4
12.1.5.2
11.6.5.2
15.0.1.3
14.1.2.4
15.0.1.2
15.1.0.2
15.1.0.1
12.1.5.1
14.1.2.3
14.1.0.6
14.0.0.5
11.6.5.1
13.1.3.1
15.0.1.1
13.1.3.2
11.5.7
11.5.8
11.5.9
11.5.10
11.6.5
12.1.4
12.1.5
15.0.1
15.1.0
15.0.0
14.1.2.1.0.122.4-ENG Hotfix
14.1.2.1.0.115.4-ENG Hotfix
14.1.2.1.0.111.4-ENG Hotfix
14.1.2.1.0.105.4-ENG Hotfix
14.1.2.1.0.99.4-ENG Hotfix
14.1.2.1.0.97.4-ENG Hotfix
14.1.2.1.0.34.4-ENG Hotfix
14.1.2.1.0.16.4-ENG Hotfix
14.1.2.1.0.14.4-ENG Hotfix
14.1.2.1.0.46.4-ENG Hotfix
14.1.2.0.32.37-ENG Hotfix
14.1.2.0.18.37-ENG Hotfix
14.1.2.0.11.37-ENG Hotfix
14.1.0.6.0.70.9-ENG Hotfix
14.1.0.6.0.68.9-ENG Hotfix
14.1.0.6.0.14.9-ENG Hotfix
14.1.0.6.0.11.9-ENG Hotfix
14.1.0.5.0.40.5-ENG Hotfix
14.1.0.5.0.36.5-ENG Hotfix
14.1.0.5.0.15.5-ENG Hotfix
14.1.0.3.0.99.6-ENG Hotfix
14.1.0.3.0.97.6-ENG Hotfix
14.1.0.3.0.79.6-ENG Hotfix
15.0.1.0.48.11-ENG Hotfix
15.0.1.0.33.11-ENG Hotfix
13.1.1.5
14.0.1
14.0.0
14.1.2
14.1.1
14.1.0
13.1.1
14.0.1.1
14.1.2.1
13.1.3
11.6.4
13.1.0.8
13.0.0 HF1
12.1.3.2
12.1.3.4
13.1.0.6
12.1.3.1
13.0.1
11.5.6
11.5.5
11.5.4 HF4
11.6.3
12.1.3
13.1.0.4
13.1.0.3
13.1.0.2
13.1.0.1
13.1.0
11.5.3
11.5.2
11.5.1
11.5.0
11.6.2
11.4.0
11.2.1
11.5.4
11.5.1 HF6
11.6.0
12.0.1
12.1.2 HF1
13.0.0
12.1.0 HF1
12.0.0 HF4
12.0.0 HF3
12.0.0 HF1
12.1.2
12.0.0
11.6.1 HF1
12.1.1
12.1.0
11.6.1
Vulnerabilities (171)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU122359 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CVE-2026-22548 |
CWE-362 | Medium | 17.1.3 | 05.02.2026 |
SB2026020531 |
||
| #VU117358 - Unchecked Return Value CVE-2025-61935 |
CWE-252 | Medium | 15.1.10.8, 17.1.3, 17.5.1 | 17.10.2025 |
SB2025101758 |
||
| #VU103721 - Out-of-bounds write CVE-2025-24326 |
CWE-787 | Medium | 15.1.10.6.0.11.6, 16.1.5, 17.1.2 | 07.02.2025 |
SB2025020738 |
||
| #VU71787 - Resource exhaustion CVE-2023-23552 |
CWE-400 | Medium | 14.1.5.3, 15.1.8, 16.1.3.3, 17.0.0.2 | 03.02.2023 |
SB2023020310 |
||
| #VU67532 - Use After Free CVE-2022-40674 |
CWE-416 | High | - | 21.09.2022 |
SB2022092118 SB2022092119 SB2022092317 and 111 more |
||
| #VU59846 - Unrestricted Upload of File with Dangerous Type CVE-2022-23026 |
CWE-434 | Medium | 14.1.4.5, 15.1.4.1, 16.1.2 | 19.01.2022 |
SB2022011950 |
||
| #VU59844 - Improper Restriction of XML External Entity Reference ('XXE') CVE-2022-23031 |
CWE-611 | Low | 14.1.4.4, 15.1.4, 16.1.1 | 19.01.2022 |
SB2022011948 |
||
| #VU56113 - Permissions, Privileges, and Access Controls CVE-2021-23031 |
CWE-264 | Medium | 11.6.5.3, 12.1.6, 13.1.4, 14.1.4.1, 15.1.3, 16.0.1.2, 16.1.0 | 26.08.2021 |
SB2021082612 |
||
| #VU56088 - Improper input validation CVE-2021-23045 |
CWE-20 | Low | 13.1.4.1, 14.1.4.3, 15.1.3.1, 16.0.1.2, 16.1.0 | 25.08.2021 |
SB2021082512 |
||
| #VU52754 - Insufficient Session Expiration |
CWE-613 | Low | 13.1.4, 14.1.4, 15.1.3, 16.0.1.1 | 29.04.2021 |
SB2021042921 |
||
| #VU52749 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2021-23009 |
CWE-835 | Medium | 15.1.3, 16.0.1.1 | 29.04.2021 |
SB2021042917 |
||
| #VU52747 - Improper Authorization CVE-2021-23014 |
CWE-285 | Low | 14.1.4, 15.1.3, 16.0.1.1 | 29.04.2021 |
SB2021042915 |
||
| #VU52746 - Improper input validation CVE-2021-23010 |
CWE-20 | Medium | 12.1.5.3, 13.1.3.5, 14.1.3.1, 15.1.2, 16.0.1.1 | 29.04.2021 |
SB2021042914 |
||
| #VU51496 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2021-22990 |
CWE-78 | Medium | 11.6.5.3, 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, 16.0.1.1 | 16.03.2021 |
SB2021031609 |
||
| #VU51495 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2021-22989 |
CWE-78 | Medium | 11.6.5.3, 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, 16.0.1.1 | 16.03.2021 |
SB2021031608 |
||
| #VU51494 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2021-22988 |
CWE-78 | High | 11.6.5.3, 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, 16.0.1.1 | 16.03.2021 |
SB2021031607 |
||
| #VU51493 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2021-22987 |
CWE-78 | High | 11.6.5.3, 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, 16.0.1.1 | 16.03.2021 |
SB2021031606 |
||
| #VU51492 - Memory corruption CVE-2021-22992 |
CWE-119 | High | 11.6.5.3, 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, 16.0.1.1 | 16.03.2021 |
SB2021031605 |
||
| #VU51491 - Resource Management Errors CVE-2021-23003 |
CWE-399 | Medium | 11.6.5.3, 12.1.5.3, 13.1.3.6, 14.1.3.1, 15.1.2, 16.0.1.1 | 16.03.2021 |
SB2021031604 |
||
| #VU51490 - Resource Management Errors CVE-2021-23000 |
CWE-399 | Medium | 12.1.5.3 | 16.03.2021 |
SB2021031603 |
Showing elements 1 - 20 out of 171