Big Ip

Vendor:

First CVE: Feb 19, 2008 · Active for 18 years

128
Total CVEs
More Total CVEs than 99% of tracked products
16.0
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.8%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Big Ip over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 19, 2008
18 years ago
Most Recent CVE
May 13, 2026
72 days ago

CVE Severity & Scoring

Big Ip128 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local7 (5.5%)
Network116 (90.6%)
Unknown3 (2.3%)
Physical1 (0.8%)
Adjacent Network1 (0.8%)
Attack Complexity
Low117 (91.4%)
High8 (6.3%)
Unknown3 (2.3%)
User Interaction
None112 (87.5%)
Unknown3 (2.3%)
Required13 (10.2%)
Privileges Required
Low16 (12.5%)
High31 (24.2%)
None78 (60.9%)
Unknown3 (2.3%)

Top CVEs

Signals from CVEs in this product scope (128 CVEs).

128 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).   Note: Software versions which have reached
Oct 15, 20259.880YESNO
A format string vulnerability exists in iControl SOAP that allows an authenticated attacker to crash the iControl SOAP CGI process or, potentially execute arbitrary code. In appli
Feb 1, 20238.567NONO
Multiple stack-based buffer overflows in the legacy mod_jk2 2.0.3-DEV and earlier Apache module allow remote attackers to execute arbitrary code via a long (1) Host header, or (2)
Feb 19, 20087.554NOYES
When running in Appliance mode, a command injection vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command which may allow an authenticated attac
May 7, 20258.743NONO
A vulnerability exists in iControl REST where a highly privileged, authenticated attacker with at least the Manager role can create configuration objects that allow running arbitra
May 13, 20269.136NONO
A vulnerability exists in BIG-IP systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can modify configuration objects resulting
May 13, 20268.735NONO
An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects through iControl SOAP resulting in privilege escalation.  Note: Sof
May 13, 20268.735NONO
When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with the Resour
May 13, 20268.735NONO
When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful exploit can allow the attacker
May 13, 20268.734NONO
A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system comman
May 13, 20268.734NONO

Exploit Exposure

Signals from CVEs in this product scope (128 CVEs).

CISA KEV
1 CVE
0.8% of CVEs· 96th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
1.6% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (128 CVEs).

Media Mentions

Signals from CVEs in this product scope (128 CVEs).

Top CNAs Publishing CVEs For Big Ip

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.4.316.82.4%01
9.2.3.3017.541.5%01
11.3.014.32.1%00