Big Ip Advanced Web Application Firewall

Vendor:

First CVE: Jul 1, 2020 · Active for 6 years

194
Total CVEs
More Total CVEs than 100% of tracked products
27.7
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 46% of tracked products
3.1%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Big Ip Advanced Web Application Firewall over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 1, 2020
6 years ago
Most Recent CVE
May 13, 2026
76 days ago

CVE Severity & Scoring

Big Ip Advanced Web Application Firewall194 CVEs
All CVEs353,240 CVEs
LowMediumHighCritical
Attack Vector
Local8 (4.1%)
Network184 (94.8%)
Unknown0 (0.0%)
Physical1 (0.5%)
Adjacent Network1 (0.5%)
Attack Complexity
Low183 (94.3%)
High11 (5.7%)
Unknown0 (0.0%)
User Interaction
None174 (89.7%)
Unknown0 (0.0%)
Required20 (10.3%)
Privileges Required
Low34 (17.5%)
High37 (19.1%)
None123 (63.4%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (194 CVEs).

194 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.
Mar 31, 20219.899YESYES
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Co
Jul 1, 20209.899YESYES
Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addre
Oct 26, 20239.898YESYES
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through
Oct 10, 20237.597YESYES
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, undisclosed requests to a virtual serve
Mar 31, 20219.890YESNO
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, a malicious HTT
Mar 31, 20219.871NONO
An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may allow an authenticated attacker with network access to the Configuration utility
Oct 26, 20238.869YESNO
When running in Appliance mode, a command injection vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command which may allow an authenticated attac
May 7, 20258.743NONO
The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-s
Nov 11, 20217.538NONO
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3 when running in
Mar 31, 20219.936NONO

Exploit Exposure

Signals from CVEs in this product scope (194 CVEs).

CISA KEV
6 CVEs
3.1% of CVEs· 98th percentile
Metasploit
3 CVEs
1.5% of CVEs· 97th percentile
Nuclei
3 CVEs
1.5% of CVEs· 96th percentile
ExploitDB
3 CVEs
1.5% of CVEs· 85th percentile

Social Chatter

Signals from CVEs in this product scope (194 CVEs).

Media Mentions

Signals from CVEs in this product scope (194 CVEs).

Top CNAs Publishing CVEs For Big Ip Advanced Web Application Firewall

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
21.0.0297.50.3%00
17.5.077.03.5%00
17.1.0116.99.5%11
17.0.037.50.7%00
16.1.256.80.9%00
16.1.147.20.9%00
16.1.047.20.9%00
16.0.1.115.31.6%00
16.0.117.50.9%00
15.1.547.20.9%00
15.1.4.115.30.6%00
15.1.447.20.9%00
15.1.347.20.9%00
15.1.247.20.9%00
15.1.147.20.9%00
15.1.057.00.8%00
14.1.515.30.6%00
14.1.456.81.1%00
14.1.347.20.9%00
14.1.247.20.9%00