Known vulnerabilities in BIG-IP ASM - page 5
Vendor:
F5 Networks
Software:
BIG-IP ASM
Software CPE:
cpe:2.3:h:f5_networks:big-ip_asm:*:*:*:*:*:*:*:*
Website:
https://f5.com/
Total vulnerabilities:
171
Public exploits:
14
Known exploited (KEV):
3
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
12.1.3.3
13.1.3.3
13.1.1.4
13.1.1.3
13.1.1.2
13.1.1.1
13.1.0.7
13.1.0.5
14.1.2.2
15.1.0.3
17.5.0
17.1.1
17.1.0
15.1.10.7
15.1.10.5
15.1.10.4
15.1.10.3
15.1.10.2
15.1.10.1
15.1.10.0
17.5.1
15.1.10.8
17.1.3
15.1.10.6.0.11.6
16.1.5
17.1.2
12.1.4.1
14.1.4.2
17.0.0.1
16.1.3.2
16.1.3.1
16.1.3
14.1.5.2
14.1.5.1
14.1.5
14.1.5.3
15.1.8
16.1.3.3
17.0.0.2
17.0.0
14.1.4.5
15.1.4.1
16.1.2
14.1.4.4
15.1.4
16.1.1
14.1.4.1
12.1.6
16.1.0
13.1.4.1
14.1.4.3
15.1.3.1
16.0.1.2
13.1.4
15.1.3
11.6.5.3
12.1.5.3
14.1.4
13.1.3.6
15.1.2.1
16.0.1.1
14.1.3.1
14.1.2.8
13.1.3.5
14.1.3
16.0.1
15.1.2
15.1.1
13.0.0 HF3
12.1.2 HF2
11.6.2 HF1
15.1.0.5
14.1.2.7
16.0.0
14.1.2-0.89.37
14.1.2.5
15.0.1.4
15.1.0.4
14.1.2.6
13.1.3.4
12.1.5.2
11.6.5.2
15.0.1.3
14.1.2.4
15.0.1.2
15.1.0.2
15.1.0.1
12.1.5.1
14.1.2.3
14.1.0.6
14.0.0.5
11.6.5.1
13.1.3.1
15.0.1.1
13.1.3.2
11.5.7
11.5.8
11.5.9
11.5.10
11.6.5
12.1.4
12.1.5
15.0.1
15.1.0
15.0.0
14.1.2.1.0.122.4-ENG Hotfix
14.1.2.1.0.115.4-ENG Hotfix
14.1.2.1.0.111.4-ENG Hotfix
14.1.2.1.0.105.4-ENG Hotfix
14.1.2.1.0.99.4-ENG Hotfix
14.1.2.1.0.97.4-ENG Hotfix
14.1.2.1.0.34.4-ENG Hotfix
14.1.2.1.0.16.4-ENG Hotfix
14.1.2.1.0.14.4-ENG Hotfix
14.1.2.1.0.46.4-ENG Hotfix
14.1.2.0.32.37-ENG Hotfix
14.1.2.0.18.37-ENG Hotfix
14.1.2.0.11.37-ENG Hotfix
14.1.0.6.0.70.9-ENG Hotfix
14.1.0.6.0.68.9-ENG Hotfix
14.1.0.6.0.14.9-ENG Hotfix
14.1.0.6.0.11.9-ENG Hotfix
14.1.0.5.0.40.5-ENG Hotfix
14.1.0.5.0.36.5-ENG Hotfix
14.1.0.5.0.15.5-ENG Hotfix
14.1.0.3.0.99.6-ENG Hotfix
14.1.0.3.0.97.6-ENG Hotfix
14.1.0.3.0.79.6-ENG Hotfix
15.0.1.0.48.11-ENG Hotfix
15.0.1.0.33.11-ENG Hotfix
13.1.1.5
14.0.1
14.0.0
14.1.2
14.1.1
14.1.0
13.1.1
14.0.1.1
14.1.2.1
13.1.3
11.6.4
13.1.0.8
13.0.0 HF1
12.1.3.2
12.1.3.4
13.1.0.6
12.1.3.1
13.0.1
11.5.6
11.5.5
11.5.4 HF4
11.6.3
12.1.3
13.1.0.4
13.1.0.3
13.1.0.2
13.1.0.1
13.1.0
11.5.3
11.5.2
11.5.1
11.5.0
11.6.2
11.4.0
11.2.1
11.5.4
11.5.1 HF6
11.6.0
12.0.1
12.1.2 HF1
13.0.0
12.1.0 HF1
12.0.0 HF4
12.0.0 HF3
12.0.0 HF1
12.1.2
12.0.0
11.6.1 HF1
12.1.1
12.1.0
11.6.1
Vulnerabilities (171)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU46075 - Improper input validation CVE-2020-5925 |
CWE-20 | Medium | 11.6.5.2, 12.1.5.2, 13.1.3.4, 14.1.2.7, 15.0.1.4, 15.1.0.5, 16.0.0 | 26.08.2020 |
SB2020082609 |
||
| #VU46073 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2020-5927 |
CWE-79 | Low | 14.1.2.7, 15.0.1.4, 15.1.0.5, 16.0.0 | 26.08.2020 |
SB2020082608 |
||
| #VU46071 - Improper Certificate Validation CVE-2020-5913 |
CWE-295 | Medium | 12.1.5.2, 14.1.2-0.89.37, 14.1.2.5, 15.1.0.2, 16.0.0 | 26.08.2020 |
SB2020082607 |
||
| #VU31791 - Permissions, Privileges, and Access Controls CVE-2020-5907 |
CWE-264 | Low | 11.6.5.2, 12.1.5.2, 13.1.3.4, 14.1.2.4, 15.0.1.4, 15.1.0.4 | 23.07.2020 |
SB2020070133 |
||
| #VU31790 - Incorrect Default Permissions CVE-2020-5906 |
CWE-276 | Medium | 12.1.5.2, 13.1.3.4 | 23.07.2020 |
SB2020070134 |
||
| #VU31789 - Cross-Site Request Forgery (CSRF) CVE-2020-5904 |
CWE-352 | Low | 12.1.5.2, 13.1.3.4, 14.1.2.6, 15.0.1.4, 15.1.0.4 | 23.07.2020 |
SB2020070134 |
||
| #VU31788 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2020-5903 |
CWE-79 | Low | 12.1.5.2, 13.1.3.4, 14.1.2.6, 15.0.1.4, 15.1.0.4 | 23.07.2020 |
SB2020070134 |
||
| #VU29449 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2020-5905 |
CWE-79 | Low | - | 02.07.2020 |
SB2020070204 |
||
| #VU29442 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2020-5902 |
CWE-78 | High | 11.6.5.2, 12.1.5.2, 13.1.3.4, 14.1.2.6, 15.1.0.4 | 01.07.2020 |
SB2020070120 |
||
| #VU27561 - Improper input validation CVE-2020-5872 |
CWE-20 | Medium | 12.1.5, 13.1.3.2, 14.0.1.1, 14.1.2.4, 15.0.0 | 06.05.2020 |
SB2020050613 |
||
| #VU27528 - Improper input validation CVE-2020-5875 |
CWE-20 | Medium | 14.1.2.4, 15.0.1.1, 15.1.0 | 05.05.2020 |
SB2020050510 |
||
| #VU27520 - Missing Encryption of Sensitive Data CVE-2020-5886 |
CWE-311 | Medium | 14.1.2.4, 15.1.0.2 | 05.05.2020 |
SB2020050509 |
||
| #VU27518 - Security Features CVE-2020-5884 |
CWE-254 | Medium | 16.0.0 | 05.05.2020 |
SB2020050507 |
||
| #VU27517 - Improper Authentication CVE-2020-5888 |
CWE-287 | Medium | 14.1.2.4, 15.0.1.3, 15.1.0.2 | 05.05.2020 |
SB2020050509 |
||
| #VU27516 - Missing Encryption of Sensitive Data CVE-2020-5879 |
CWE-311 | Medium | 12.0.0 | 05.05.2020 |
SB2020050508 |
||
| #VU49042 - Missing release of memory after effective lifetime CVE-2020-5883 |
CWE-401 | Medium | 13.1.3.2, 14.0.1.1, 14.1.2.4, 15.0.1.1 | 30.04.2020 |
SB2020043038 |
||
| #VU27467 - Unrestricted Upload of File with Dangerous Type CVE-2020-5880 |
CWE-434 | Medium | 14.1.2.4, 15.1.0 | 30.04.2020 |
SB2020043025 |
||
| #VU27395 - Authentication Bypass by Spoofing CVE-2020-11868 |
CWE-290 | Low | - | 28.04.2020 |
SB2020042822 SB2020070701 SB2020071906 and 7 more |
||
| #VU26461 - Improper input validation CVE-2020-5862 |
CWE-20 | Low | 14.1.2.3, 15.0.1.2, 15.1.0.2 | 30.03.2020 |
SB2020033009 |
||
| #VU26456 - Missing release of memory after effective lifetime CVE-2020-5861 |
CWE-401 | Low | 12.1.5.1 | 30.03.2020 |
SB2020033010 |
Showing elements 81 - 100 out of 171