cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2019-19151,https://securityvulnerability.io/vulnerability/CVE-2019-19151,Improper Access Control in BIG-IP and BIG-IQ Products by F5 Networks,"On specific versions of F5 Networks' BIG-IP and BIG-IQ products, an improper access control vulnerability allows authenticated users with low privileges to bypass normal restrictions and access system objects on the file system. This could lead to exposure of sensitive information or unauthorized operations, necessitating immediate attention and remediation.",F5,"Big-ip, Big-iq, Iworkflow, Enterprise Manager",5.5,MEDIUM,0.0004400000034365803,false,,false,false,false,,,false,false,,2019-12-23T18:03:02.000Z,0 CVE-2019-6665,https://securityvulnerability.io/vulnerability/CVE-2019-6665,Improper Input Validation in F5 BIG-IP ASM and BIG-IQ,"The vulnerability in F5 BIG-IP ASM and BIG-IQ allows an attacker with access to the communication channel to manipulate the traffic between Central Policy Builder and the management components. This situation arises due to improper input validation, enabling potential interception of sensitive data during the communication process.",F5,"Big-ip Asm,Big-iq,Iworkflow,Enterprise Manager",9.4,CRITICAL,0.001970000099390745,false,,false,false,false,,,false,false,,2019-11-27T21:57:58.000Z,0 CVE-2019-6663,https://securityvulnerability.io/vulnerability/CVE-2019-6663,Anti DNS Pinning Vulnerability in F5 BIG-IP and BIG-IQ Products,"F5 BIG-IP and BIG-IQ products are susceptible to an Anti DNS Pinning (DNS Rebinding) vulnerability, which may allow attackers to exploit misuse of the DNS resolution process. This flaw affects various versions of the BIG-IP and BIG-IQ configuration utilities and can potentially enable malicious actors to craft requests that can lead to unauthorized actions on behalf of legitimate users. Proper security measures should be taken to mitigate risks associated with this vulnerability.",F5,"Big-ip, Big-iq, Iworkflow, Enterprise Manager",5.5,MEDIUM,0.0005300000193528831,false,,false,false,false,,,false,false,,2019-11-15T20:40:26.000Z,0 CVE-2019-6651,https://securityvulnerability.io/vulnerability/CVE-2019-6651,Security Flaw in BIG-IP and BIG-IQ Products from F5 Networks,"A security vulnerability exists in F5 Networks' BIG-IP and BIG-IQ products where the Configuration utility login page may not adequately secure against malicious requests. This could potentially allow an attacker to exploit the utility, increasing the risk of unauthorized access and impacting system integrity. It is crucial for users to implement recommended security practices to safeguard their environments.",F5,"Big-ip, Big-iq, Iworkflow, Enterprise Manager",5.3,MEDIUM,0.0008999999845400453,false,,false,false,false,,,false,false,,2019-09-25T17:39:36.000Z,0 CVE-2019-6642,https://securityvulnerability.io/vulnerability/CVE-2019-6642,Privilege Escalation in F5 Networks BIG-IP and BIG-IQ Products,"In specific versions of F5 Networks' BIG-IP and BIG-IQ products, a vulnerability allows authenticated users who can upload files through methods like SCP to escalate their privileges. This may enable an attacker to gain root shell access within the TMOS Shell (tmsh) interface, which subsequently allows the execution of commands through secondary programs. The ability to misuse this functionality can pose substantial risks to system integrity and confidentiality.",F5,"Big-ip, Big-iq, Iworkflow, Enterprise Manager",8.8,HIGH,0.0010400000028312206,false,,false,false,false,,,false,false,,2019-07-01T20:21:01.000Z,0 CVE-2018-15328,https://securityvulnerability.io/vulnerability/CVE-2018-15328,,"On BIG-IP 14.0.x, 13.x, 12.x, and 11.x, Enterprise Manager 3.1.1, BIG-IQ 6.x, 5.x, and 4.x, and iWorkflow 2.x, the passphrases for SNMPv3 users and trap destinations that are used for authentication and privacy are not handled by the BIG-IP system Secure Vault feature; they are written in the clear to the various configuration files.",F5,"Big-ip (ltm, Aam, Afm, Analytics, Apm, Asm, Dns, Edge Gateway, Fps, Gtm, Link Controller, Pem, Webaccelerator), Enterprise Manager, Big-iq Centralized Management, F5 Iworkflow",7.5,HIGH,0.0010400000028312206,false,,false,false,false,,,false,false,,2018-12-12T14:00:00.000Z,0 CVE-2018-15322,https://securityvulnerability.io/vulnerability/CVE-2018-15322,,"On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, 11.6.0-11.6.3.2, or 11.2.1-11.5.6, BIG-IQ Centralized Management 6.0.0-6.0.1, 5.0.0-5.4.0 or 4.6.0, BIG-IQ Cloud and Orchestration 1.0.0, iWorkflow 2.0.1-2.3.0, or Enterprise Manager 3.1.1 a BIG-IP user granted with tmsh access may cause the BIG-IP system to experience denial-of-service (DoS) when the BIG-IP user uses the tmsh utility to run the edit cli preference command and proceeds to save the changes to another filename repeatedly. This action utilises storage space on the /var partition and when performed repeatedly causes the /var partition to be full.",F5,"Big-ip (ltm, Aam, Afm, Analytics, Apm, Asm, Dns, Edge Gateway, Gtm, Link Controller, Pem, Webaccelerator, Websafe), Big-iq Centralized Management, Big-iq Cloud And Orchestration, Iworkflow, Enterprise Manager",6.5,MEDIUM,0.0007200000109151006,false,,false,false,false,,,false,false,,2018-10-31T14:00:00.000Z,0 CVE-2018-15321,https://securityvulnerability.io/vulnerability/CVE-2018-15321,,"When BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.0.5, 12.1.0-12.1.3.5, 11.6.0-11.6.3.2, or 11.2.1-11.5.6, BIG-IQ Centralized Management 5.0.0-5.4.0 or 4.6.0, BIG-IQ Cloud and Orchestration 1.0.0, iWorkflow 2.1.0-2.3.0, or Enterprise Manager 3.1.1 is licensed for Appliance Mode, Admin and Resource administrator roles can by-pass BIG-IP Appliance Mode restrictions to overwrite critical system files. Attackers of high privilege level are able to overwrite critical system files which bypasses security controls in place to limit TMSH commands. This is possible with an administrator or resource administrator roles when granted TMSH. Resource administrator roles must have TMSH access in order to perform this attack.",F5,"Big-ip (ltm, Aam, Afm, Analytics, Apm, Asm, Dns, Edge Gateway, Fps, Gtm, Link Controller, Pem, Webaccelerator), Big-iq Centralized Management, Big-iq Cloud And Orchestration, Iworkflow, Enterprise Manager",4.9,MEDIUM,0.0005000000237487257,false,,false,false,false,,,false,false,,2018-10-31T14:00:00.000Z,0 CVE-2018-5540,https://securityvulnerability.io/vulnerability/CVE-2018-5540,,"On F5 BIG-IP 13.0.0-13.0.1, 12.1.0-12.1.3.3, 11.6.0-11.6.3.1, or 11.5.1-11.5.6, Enterprise Manager 3.1.1, BIG-IQ Centralized Management 5.0.0-5.1.0, BIG-IQ Cloud and Orchestration 1.0.0, or F5 iWorkflow 2.1.0-2.3.0 the big3d process does not irrevocably minimize group privileges at start up.",F5,"Big-ip (dns, Gtm),Enterprise Manager,Big-iq Centralized Management,Big-iq Cloud And Orchestration,F5 Iworkflow",4.4,MEDIUM,0.0007900000200606883,false,,false,false,false,,,false,false,,2018-07-19T14:29:00.000Z,0 CVE-2018-5516,https://securityvulnerability.io/vulnerability/CVE-2018-5516,,"On F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.2, or 11.2.1-11.6.3.1, Enterprise Manager 3.1.1, BIG-IQ Centralized Management 5.0.0-5.4.0 or 4.6.0, BIG-IQ Cloud and Orchestration 1.0.0, or F5 iWorkflow 2.0.2-2.3.0, authenticated users granted TMOS Shell (tmsh) access can access objects on the file system which would normally be disallowed by tmsh restrictions. This allows for authenticated, low privileged attackers to exfiltrate objects on the file system which should not be allowed.",F5,"Big-ip (ltm, Aam, Afm, Analytics, Apm, Asm, Dns, Edge Gateway, Gtm, Link Controller, Pem, Webaccelerator, Websafe),Enterprise Manager,Big-iq Centralized Management,Big-iq Cloud And Orchestration,Iworkflow",4.7,MEDIUM,0.0004900000058114529,false,,false,false,false,,,false,false,,2018-05-02T13:29:00.000Z,0 CVE-2017-6128,https://securityvulnerability.io/vulnerability/CVE-2017-6128,,"An attacker may be able to cause a denial-of-service (DoS) attack against the sshd component in F5 BIG-IP, Enterprise Manager, BIG-IQ, and iWorkflow.",F5,"Big-ip Ltm, Aam, Afm, Analytics, Apm, Asm, Edge Gateway, Gtm, Link Controller, Pem, Psm, Webaccelerator, Websafe,Enterprise Manager,Big-iq Cloud, Device, Security, Adc, Centralized Management, Cloud And Orchestration,Iworkflow",7.5,HIGH,0.002580000087618828,false,,false,false,false,,,false,false,,2017-05-01T15:00:00.000Z,0