NA - CVE-2024-7596 - Proposed Generic UDP Encapsulation (GUE) (IETF...
Proposed Generic UDP Encapsulation (GUE) (IETF Draft) do not validate or verify the source of a network packet allowing an attacker to spoof and route arbitrary traffic via an exposed network...
NA - CVE-2025-20029 - Command injection vulnerability exists in...
Command injection vulnerability exists in iControl REST and BIG-IP TMOS Shell (tmsh) save command, which may allow an authenticated attacker to execute arbitrary system commands. Note:...
NA - CVE-2025-20045 - When SIP session Application Level Gateway mode...
When SIP session Application Level Gateway mode (ALG) profile with Passthru Mode enabled and SIP router ALG profile are configured on a Message Routing type virtual server, undisclosed traffic can...
NA - CVE-2025-20058 - When a BIG-IP message routing profile is...
When a BIG-IP message routing profile is configured on a virtual server, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of...
NA - CVE-2025-21087 - When Client or Server SSL profiles are...
When Client or Server SSL profiles are configured on a Virtual Server, or DNSSEC signing operations are in use, undisclosed traffic can cause an increase in memory and CPU resource utilization....
NA - CVE-2025-21091 - When SNMP v1 or v2c are disabled on the BIG-IP,...
When SNMP v1 or v2c are disabled on the BIG-IP, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support...
NA - CVE-2025-22846 - When SIP Session and Router ALG profiles are...
When SIP Session and Router ALG profiles are configured on a Message Routing type virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note:...
NA - CVE-2025-22891 - When BIG-IP PEM Control Plane listener Virtual...
When BIG-IP PEM Control Plane listener Virtual Server is configured with Diameter Endpoint profile, undisclosed traffic can cause the Virtual Server to stop processing new client connections and an...
NA - CVE-2025-23239 - When running in Appliance mode, an...
When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a...
NA - CVE-2025-23412 - When BIG-IP APM Access Profile is configured on...
When BIG-IP APM Access Profile is configured on a virtual server, undisclosed request can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS)...