Big Ip Next Central Manager

Vendor:

First CVE: May 8, 2024 · Active for 2 years

12
Total CVEs
More Total CVEs than 91% of tracked products
6.0
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 37% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Big Ip Next Central Manager over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 8, 2024
2 years ago
Most Recent CVE
Aug 13, 2025
349 days ago

CVE Severity & Scoring

Big Ip Next Central Manager12 CVEs
All CVEs353,240 CVEs
MediumHigh
Attack Vector
Local2 (16.7%)
Network10 (83.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (83.3%)
High2 (16.7%)
Unknown0 (0.0%)
User Interaction
None10 (83.3%)
Unknown0 (0.0%)
Required2 (16.7%)
Privileges Required
Low1 (8.3%)
High1 (8.3%)
None10 (83.3%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An SQL injection vulnerability exists in the BIG-IP Next Central Manager API (URI).  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
May 8, 20247.528NONO
An OData injection vulnerability exists in the BIG-IP Next Central Manager API (URI).  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
May 8, 20247.528NONO
When a BIG-IP HTTP/2 httprouter profile is configured on a virtual server, undisclosed responses can cause an increase in memory resource utilization.  Note: Software versions whic
May 7, 20257.522NONO
The Central Manager user session refresh token does not expire when a user logs out.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Aug 14, 20248.822NONO
An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit (HTTP/2 MadeYouReset Att
Aug 13, 20255.321NONO
When a Stream Control Transmission Protocol (SCTP) profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Softw
May 7, 20257.521NONO
An improper certificate validation vulnerability exists in BIG-IP Next Central Manager and may allow an attacker to impersonate an Instance Provider system.  Note: Software version
May 8, 20246.820NONO
When BIG-IP Next Central Manager is running, undisclosed requests to the BIG-IP Next Central Manager API can cause the BIG-IP Next Central Manager Node's Kubernetes service to term
Feb 5, 20256.519NONO
BIG-IP Next Central Manager (CM) may allow an unauthenticated, remote attacker to obtain the BIG-IP Next LTM/WAF instance credentials.  Note: Software versions which have reached
May 8, 20247.419NONO
When generating QKView of BIG-IP Next instance from the BIG-IP Next Central Manager (CM), F5 iHealth credentials will be logged in the BIG-IP Central Manager logs.  Note: Software
Aug 14, 20245.517NONO

Exploit Exposure

Signals from CVEs in this product scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (12 CVEs).

Media Mentions

Signals from CVEs in this product scope (12 CVEs).

Top CNAs Publishing CVEs For Big Ip Next Central Manager

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
20.3.015.30.5%00
20.2.117.50.4%00
20.2.027.50.4%00
20.1.018.80.4%00