Show filters
273 Total Results
Displaying 111-120 of 273
Sort by:
Attacker Value
Unknown

CVE-2019-6608

Disclosure Date: March 28, 2019 (last updated November 27, 2024)
On BIG-IP 11.5.1-11.6.3, 12.1.0-12.1.3, 13.0.0-13.1.1.1, and 14.0.0-14.0.0.2, under certain conditions, the snmpd daemon may leak memory on a multi-blade BIG-IP vCMP guest when processing authorized SNMP requests.
0
Attacker Value
Unknown

CVE-2019-6606

Disclosure Date: March 28, 2019 (last updated November 27, 2024)
On BIG-IP 11.5.1-11.6.3.4, 12.1.0-12.1.3.7, 13.0.0-13.1.1.3, and 14.0.0-14.0.0.2, when processing certain SNMP requests with a request-id of 0, the snmpd process may leak a small amount of memory.
0
Attacker Value
Unknown

CVE-2019-6605

Disclosure Date: March 28, 2019 (last updated November 27, 2024)
On BIG-IP 11.5.1-11.5.8, 11.6.1-11.6.3, and 12.0.x, an undisclosed sequence of packets received by an SSL virtual server and processed by an associated Client SSL or Server SSL profile may cause a denial of service.
0
Attacker Value
Unknown

CVE-2019-6602

Disclosure Date: March 28, 2019 (last updated November 27, 2024)
In BIG-IP 11.5.1-11.5.8 and 11.6.1-11.6.3, the Configuration Utility login page may not follow best security practices when handling a malicious request.
0
Attacker Value
Unknown

CVE-2019-6600

Disclosure Date: March 13, 2019 (last updated November 27, 2024)
In BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.3, 12.1.0-12.1.3.7, 11.6.1-11.6.3.2, or 11.5.1-11.5.8, when remote authentication is enabled for administrative users and all external users are granted the "guest" role, unsanitized values can be reflected to the client via the login page. This can lead to a cross-site scripting attack against unauthenticated clients.
Attacker Value
Unknown

CVE-2019-6597

Disclosure Date: March 13, 2019 (last updated November 27, 2024)
In BIG-IP 13.0.0-13.1.1.1, 12.1.0-12.1.3.7, 11.6.1-11.6.3.2, or 11.5.1-11.5.8 or Enterprise Manager 3.1.1, when authenticated administrative users run commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, restrictions on allowed commands may not be enforced.
0
Attacker Value
Unknown

CVE-2019-6598

Disclosure Date: March 13, 2019 (last updated November 27, 2024)
In BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, 11.6.1-11.6.3.2, or 11.5.1-11.5.8 or Enterprise Manager 3.1.1, malformed requests to the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, may lead to disruption of TMUI services. This attack requires an authenticated user with any role (other than the No Access role). The No Access user role cannot login and does not have the access level to perform the attack.
0
Attacker Value
Unknown

CVE-2019-6594

Disclosure Date: February 26, 2019 (last updated November 27, 2024)
On BIG-IP 11.5.1-11.6.3.2, 12.1.3.4-12.1.3.7, 13.0.0 HF1-13.1.1.1, and 14.0.0-14.0.0.2, Multi-Path TCP (MPTCP) does not protect against multiple zero length DATA_FINs in the reassembly queue, which can lead to an infinite loop in some circumstances.
0
Attacker Value
Unknown

CVE-2019-6593

Disclosure Date: February 26, 2019 (last updated November 27, 2024)
On BIG-IP 11.5.1-11.5.4, 11.6.1, and 12.1.0, a virtual server configured with a Client SSL profile may be vulnerable to a chosen ciphertext attack against CBC ciphers. When exploited, this may result in plaintext recovery of encrypted messages through a man-in-the-middle (MITM) attack, despite the attacker not having gained access to the server's private key itself. (CVE-2019-6593 also known as Zombie POODLE and GOLDENDOODLE.)
0
Attacker Value
Unknown

CVE-2019-6592

Disclosure Date: February 26, 2019 (last updated November 27, 2024)
On BIG-IP 14.1.0-14.1.0.1, TMM may restart and produce a core file when validating SSL certificates in client SSL or server SSL profiles.
0