target entity

F5

7 source-linked records in the current knowledge graph.

high

CVE-2025-53521: F5 BIG-IP Stack-Based Buffer Overflow Vulnerability

F5 BIG-IP APM contains a stack-based buffer overflow vulnerability that could allow a threat actor to achieve remote code execution. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-53521EPSS 2.2%BIG-IPF5
CISA KEV ↗ · unattributed attribution
high

CVE-2023-46748: F5 BIG-IP Configuration Utility SQL Injection Vulnerability

F5 BIG-IP Configuration utility contains an SQL injection vulnerability that may allow an authenticated attacker with network access through the BIG-IP management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46747. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-46747CVE-2023-46748EPSS 96.5%BIG-IP Configuration UtilityF5
CISA KEV ↗ · unattributed attribution
high

CVE-2023-46747: F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability

F5 BIG-IP Configuration utility contains an authentication bypass using an alternate path or channel vulnerability due to undisclosed requests that may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46748. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-46747CVE-2023-46748EPSS 96.5%BIG-IP Configuration UtilityF5
CISA KEV ↗ · unattributed attribution
high

CVE-2022-1388: F5 BIG-IP Missing Authentication Vulnerability

F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code execution, creation or deletion of files, or disabling services. Required action: Apply updates per vendor instructions.

CVE-2022-1388EPSS 100.0%BIG-IPF5
CISA KEV ↗ · unattributed attribution
high

CVE-2021-22986: F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability

F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system commands, create or delete files, and disable services. Required action: Apply updates per vendor instructions.

CVE-2021-22986EPSS 99.9%BIG-IP and BIG-IQ Centralized ManagementF5
CISA KEV ↗ · unattributed attribution