Known vulnerabilities in BIG-IP ASM 14.1.3 - page 2
Vendor:
F5 Networks
Software:
BIG-IP ASM
Version:
14.1.3
Software CPE:
cpe:2.3:h:f5_networks:big-ip_asm:*:*:*:*:*:*:*:*
Website:
https://f5.com/
Total vulnerabilities:
55
Public exploits:
8
Known exploited (KEV):
2
Highest CVSSv4 Score:
9.3
Vulnerabilities by Severity
12.1.3.3
13.1.3.3
13.1.1.4
13.1.1.3
13.1.1.2
13.1.1.1
13.1.0.7
13.1.0.5
14.1.2.2
15.1.0.3
17.5.0
17.1.1
17.1.0
15.1.10.7
15.1.10.5
15.1.10.4
15.1.10.3
15.1.10.2
15.1.10.1
15.1.10.0
17.5.1
15.1.10.8
17.1.3
15.1.10.6.0.11.6
16.1.5
17.1.2
12.1.4.1
14.1.4.2
17.0.0.1
16.1.3.2
16.1.3.1
16.1.3
14.1.5.2
14.1.5.1
14.1.5
14.1.5.3
15.1.8
16.1.3.3
17.0.0.2
17.0.0
14.1.4.5
15.1.4.1
16.1.2
14.1.4.4
15.1.4
16.1.1
14.1.4.1
12.1.6
16.1.0
13.1.4.1
14.1.4.3
15.1.3.1
16.0.1.2
13.1.4
15.1.3
11.6.5.3
12.1.5.3
14.1.4
13.1.3.6
15.1.2.1
16.0.1.1
14.1.3.1
14.1.2.8
13.1.3.5
14.1.3
16.0.1
15.1.2
15.1.1
13.0.0 HF3
12.1.2 HF2
11.6.2 HF1
15.1.0.5
14.1.2.7
16.0.0
14.1.2-0.89.37
14.1.2.5
15.0.1.4
15.1.0.4
14.1.2.6
13.1.3.4
12.1.5.2
11.6.5.2
15.0.1.3
14.1.2.4
15.0.1.2
15.1.0.2
15.1.0.1
12.1.5.1
14.1.2.3
14.1.0.6
14.0.0.5
11.6.5.1
13.1.3.1
15.0.1.1
13.1.3.2
11.5.7
11.5.8
11.5.9
11.5.10
11.6.5
12.1.4
12.1.5
15.0.1
15.1.0
15.0.0
14.1.2.1.0.122.4-ENG Hotfix
14.1.2.1.0.115.4-ENG Hotfix
14.1.2.1.0.111.4-ENG Hotfix
14.1.2.1.0.105.4-ENG Hotfix
14.1.2.1.0.99.4-ENG Hotfix
14.1.2.1.0.97.4-ENG Hotfix
14.1.2.1.0.34.4-ENG Hotfix
14.1.2.1.0.16.4-ENG Hotfix
14.1.2.1.0.14.4-ENG Hotfix
14.1.2.1.0.46.4-ENG Hotfix
14.1.2.0.32.37-ENG Hotfix
14.1.2.0.18.37-ENG Hotfix
14.1.2.0.11.37-ENG Hotfix
14.1.0.6.0.70.9-ENG Hotfix
14.1.0.6.0.68.9-ENG Hotfix
14.1.0.6.0.14.9-ENG Hotfix
14.1.0.6.0.11.9-ENG Hotfix
14.1.0.5.0.40.5-ENG Hotfix
14.1.0.5.0.36.5-ENG Hotfix
14.1.0.5.0.15.5-ENG Hotfix
14.1.0.3.0.99.6-ENG Hotfix
14.1.0.3.0.97.6-ENG Hotfix
14.1.0.3.0.79.6-ENG Hotfix
15.0.1.0.48.11-ENG Hotfix
15.0.1.0.33.11-ENG Hotfix
13.1.1.5
14.0.1
14.0.0
14.1.2
14.1.1
14.1.0
13.1.1
14.0.1.1
14.1.2.1
13.1.3
11.6.4
13.1.0.8
13.0.0 HF1
12.1.3.2
12.1.3.4
13.1.0.6
12.1.3.1
13.0.1
11.5.6
11.5.5
11.5.4 HF4
11.6.3
12.1.3
13.1.0.4
13.1.0.3
13.1.0.2
13.1.0.1
13.1.0
11.5.3
11.5.2
11.5.1
11.5.0
11.6.2
11.4.0
11.2.1
11.5.4
11.5.1 HF6
11.6.0
12.0.1
12.1.2 HF1
13.0.0
12.1.0 HF1
12.0.0 HF4
12.0.0 HF3
12.0.0 HF1
12.1.2
12.0.0
11.6.1 HF1
12.1.1
12.1.0
11.6.1
Vulnerabilities (55)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU51421 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2021-22993 |
CWE-79 | Medium | 12.1.5.3, 13.1.3.6, 14.1.3.1, 15.1.2, 16.0.1.1 | 11.03.2021 |
SB2021031119 |
||
| #VU51418 - Resource exhaustion CVE-2021-23004 |
CWE-400 | Medium | 11.6.5.3, 12.1.5.3, 13.1.3.6, 14.1.3.1, 15.1.2, 16.0.1.1 | 11.03.2021 |
SB2021031116 |
||
| #VU51399 - Resource exhaustion CVE-2021-23001 |
CWE-400 | Medium | 11.6.5.3, 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, 16.0.1.1 | 11.03.2021 |
SB2021031106 |
||
| #VU51394 - Resource Management Errors CVE-2021-22999 |
CWE-399 | Medium | 14.1.4, 15.1.0 | 11.03.2021 |
SB2021031104 |
||
| #VU51391 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2021-22986 |
CWE-78 | High | 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, 16.0.1.1 | 11.03.2021 |
SB2021031102 |
||
| #VU51269 - Exposure of sensitive information to an unauthorized actor CVE-2019-18282 |
CWE-200 | Medium | - | 09.03.2021 |
SB2020011633 SB2021030902 SB2021030903 and 5 more |
||
| #VU50780 - Memory corruption CVE-2020-8625 |
CWE-119 | High | - | 17.02.2021 |
SB2021021718 SB2021021908 SB2021022703 and 28 more |
||
| #VU50620 - Resource exhaustion CVE-2021-22976 |
CWE-400 | Medium | 13.1.3.6, 14.1.3.1, 15.1.2, 16.0.1.1 | 11.02.2021 |
SB2021021117 |
||
| #VU50616 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2021-22978 |
CWE-79 | Low | 13.1.3.5, 14.1.3.1, 15.1.1, 16.0.1 | 11.02.2021 |
SB2021021113 |
||
| #VU50615 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CVE-2021-22974 |
CWE-362 | Medium | 13.1.3.6, 14.1.3.1, 15.1.2, 16.0.1.1 | 11.02.2021 |
SB2021021111 SB2021021112 |
||
| #VU50612 - Resource exhaustion CVE-2021-22975 |
CWE-400 | Medium | 14.1.3.1, 15.1.2.1, 16.0.1.1 | 11.02.2021 |
SB2021021108 |
||
| #VU50611 - Improper input validation CVE-2021-22977 |
CWE-20 | Medium | 14.1.3.1, 16.0.1.1 | 11.02.2021 |
SB2021021108 |
||
| #VU50610 - Out-of-bounds write CVE-2021-22973 |
CWE-787 | Medium | 13.1.3.5, 14.1.3.1, 15.1.2, 16.0.1.1 | 11.02.2021 |
SB2021021107 |
||
| #VU48895 - Improper Check for Certificate Revocation CVE-2020-8286 |
CWE-299 | Medium | - | 09.12.2020 |
SB2020120902 SB2020120915 SB2020120929 and 30 more |
||
| #VU48894 - Uncontrolled Recursion CVE-2020-8285 |
CWE-674 | Low | - | 09.12.2020 |
SB2020120902 SB2020120915 SB2020120928 and 37 more |
||
| #VU48893 - Exposure of sensitive information to an unauthorized actor CVE-2020-8284 |
CWE-200 | Medium | - | 09.12.2020 |
SB2020120902 SB2020120915 SB2020120927 and 31 more |
||
| #VU48896 - NULL Pointer Dereference CVE-2020-1971 |
CWE-476 | Medium | - | 08.12.2020 |
SB2020120852 SB2020120903 SB2020120905 and 91 more |
||
| #VU48569 - Resource Management Errors CVE-2020-8277 |
CWE-399 | Medium | - | 19.11.2020 |
SB2020112003 SB2020112005 SB2020102133 and 23 more |
||
| #VU50427 - Out-of-bounds read CVE-2020-10769 |
CWE-125 | Low | - | 26.06.2020 |
SB2020062625 SB2021020901 SB2022061630 and 8 more |
||
| #VU21059 - Heap-based Buffer Overflow CVE-2019-5482 |
CWE-122 | Medium | 13.1.4.1, 14.1.4.2, 15.1.4, 16.0.1.2, 16.1.0 | 11.09.2019 |
SB2019091142 SB2019091143 SB2019091201 and 28 more |
Showing elements 21 - 40 out of 55