Vulnerabilidades em F5 Networks, Inc.
140 resultadosAnálise Vexday
Com 140 CVEs catalogadas e nenhuma atualmente listada no CISA KEV, a F5 Networks apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que sugere pressão imediata reduzida em termos de ameaças confirmadas em campo. Não há vulnerabilidades críticas nem registros recentes nos últimos 90 dias, indicando estabilidade no ritmo de descobertas recentes. A CVE mais relevante no momento é CVE-2018-5511, com score EPSS de 0,1476 — valor que, embora moderado, merece monitoramento dado o histórico de produtos F5 como alvos de interesse em ambientes corporativos. A existência de ao menos um PoC público reforça a importância de manter patches aplicados mesmo na ausência de exploração confirmada.
CVE-2017-6163—In F5 BIG-IP LTM, AAM, AFM, APM, ASM, Link Controller, PEM, PSM software version 12.0.0 to 12.1.2, 11.6.0 to 11.6.1, 11.4.0 to 11.5.4, when EPSS 1.7%CVE-2017-6154—On F5 BIG-IP systems running 13.0.0, 12.1.0 - 12.1.3.1, or 11.6.1 - 11.6.2, the BIG-IP ASM bd daemon may core dump memory under some circumsEPSS 1.7%CVE-2017-6129—In F5 BIG-IP APM software version 13.0.0 and 12.1.2, in some circumstances, APM tunneled VPN flows can cause a VPN/PPP connflow to be prematEPSS 1.6%CVE-2017-6151—In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, WebAccelerator and WebSafe software version 1EPSS 1.6%CVE-2017-6135—In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and WebSafe software version 13.0.0, a slow memory leak as aEPSS 1.6%CVE-2017-6159—F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM, Websafe software version 12.0.0 to 12.1.2, 11.6.0 to 11.6.1 arEPSS 1.6%CVE-2017-6138—In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and WebSafe software version 13.0.0 and 12.1.0 - 12.1.2, malEPSS 1.6%CVE-2017-6140—On the BIG-IP 2000s, 2200s, 4000s, 4200v, i5600, i5800, i7600, i7800, i10600,i10800, and VIPRION 4450 blades, running version 11.5.0, 11.5.1EPSS 1.6%CVE-2016-9251—In F5 BIG-IP 12.0.0 through 12.1.2, an authenticated attacker may be able to cause an escalation of privileges through a crafted iControl REEPSS 1.5%CVE-2018-5522—On F5 BIG-IP 13.0.0, 12.0.0-12.1.2, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, when processing DIAMETER transactions with carefully crafted EPSS 1.5%CVE-2019-6590—On BIG-IP LTM 13.0.0 to 13.0.1 and 12.1.0 to 12.1.3.6, under certain conditions, the TMM may consume excessive resources when processing SSLEPSS 1.5%CVE-2018-5548—On BIG-IP APM 11.6.0-11.6.3, an insecure AES ECB mode is used for orig_uri parameter in an undisclosed /vdesk link of APM virtual server conEPSS 1.4%CVE-2018-15335—When APM 13.0.0-13.1.x is deployed as an OAuth Resource Server, APM becomes a client application to an external OAuth authorization server. EPSS 1.4%CVE-2018-15311—When F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.5, 11.6.0-11.6.3.2, or 11.5.1-11.5.6 is processing specially crafted TCP traffic with the LargEPSS 1.4%CVE-2017-6169—In versions 13.0.0, 12.0.0-12.1.3, or 11.6.0-11.6.2, an F5 BIG-IP virtual server using the URL categorization feature may cause the Traffic EPSS 1.4%CVE-2018-15313—On F5 BIG-IP AFM 13.0.0-13.1.1.1 and 12.1.0-12.1.3.6, there is a Reflected Cross Site Scripting vulnerability in undisclosed TMUI page.EPSS 1.4%CVE-2018-15314—On F5 BIG-IP AFM 13.0.0-13.1.1.1 and 12.1.0-12.1.3.6, there is a Reflected Cross Site Scripting vulnerability in undisclosed TMUI page.EPSS 1.4%CVE-2017-6136—In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and WebSafe software version 13.0.0 and 12.0.0 - 12.1.2, undEPSS 1.4%CVE-2017-6128—An attacker may be able to cause a denial-of-service (DoS) attack against the sshd component in F5 BIG-IP, Enterprise Manager, BIG-IQ, and iEPSS 1.4%CVE-2019-6596—In BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.1, 12.1.0-12.1.3.6, 11.6.1-11.6.3.2, or 11.5.1-11.5.8, when processing fragmented ClientHello messaEPSS 1.4%