Showing 3 vulnerabilities on this page for BIG-IP AFM

Signals CISA KEV Ransomware Nuclei
F5 vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

BIG-IP AFM NAT64 Policy Vulnerability CVE-2022-41806

In versions 16.1.x before 16.1.3.2 and 15.1.x before 15.1.5.1, when BIG-IP AFM Network Address Translation policy with IPv6/IPv4 translation rules is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization.

CWE-400Oct 19, 2022
CVSS7.5v3.1EPSS0.633%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

On F5 BIG-IP AFM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, an authenticated attacker with high privileges can upload a maliciously crafted file to the BIG-IP AFM Configuration utility, which allows an attacker to run arbitrary commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CWE-20CWE-434May 5, 2022
CVSS7.2v3.1EPSS0.868%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

On BIG-IP AFM 15.0.0-15.0.1, 14.0.0-14.1.2, and 13.1.0-13.1.3.1, when bad-actor detection is configured on a wildcard virtual server on platforms with hardware-based sPVA, the performance of the BIG-IP AFM system is degraded.

Nov 27, 2019
CVSS7.5v3.1EPSS1.2%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX