Big Ip Webaccelerator

Vendor:

First CVE: May 24, 2012 · Active for 14 years

296
Total CVEs
More Total CVEs than 100% of tracked products
19.7
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 42% of tracked products
2.4%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Big Ip Webaccelerator over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 24, 2012
14 years ago
Most Recent CVE
May 13, 2026
76 days ago

CVE Severity & Scoring

Big Ip Webaccelerator296 CVEs
All CVEs353,173 CVEs
LowMediumHighCritical
Attack Vector
Local23 (7.8%)
Network248 (83.8%)
Unknown18 (6.1%)
Physical2 (0.7%)
Adjacent Network5 (1.7%)
Attack Complexity
Low244 (82.4%)
High34 (11.5%)
Unknown18 (6.1%)
User Interaction
None253 (85.5%)
Unknown18 (6.1%)
Required25 (8.4%)
Privileges Required
Low49 (16.6%)
High51 (17.2%)
None178 (60.1%)
Unknown18 (6.1%)

Top CVEs

Signals from CVEs in this product scope (296 CVEs).

296 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a cra
Sep 24, 20149.899YESYES
Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addre
Oct 26, 20239.898YESYES
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to wri
Sep 25, 20149.898YESYES
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through
Oct 10, 20237.597YESYES
An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use thi
Sep 25, 20187.881YESYES
The iControl API in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.0 before 11.5.3 HF2 and 11.6.0 before 11.6.0 HF6, BIG-IP AAM 11.4.0 before 11.5.3 HF2 and
Dec 7, 20159.081NOYES
Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs).
Jun 19, 20197.578NONO
The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users
May 7, 20145.578YESYES
Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgme
Jun 19, 20197.576NONO
Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows a remote peer to fragment TCP resend queues significantly more than if a larger
Jun 19, 20197.575NONO

Exploit Exposure

Signals from CVEs in this product scope (296 CVEs).

CISA KEV
7 CVEs
2.4% of CVEs· 98th percentile
Metasploit
4 CVEs
1.4% of CVEs· 97th percentile
Nuclei
2 CVEs
0.7% of CVEs· 96th percentile
ExploitDB
12 CVEs
4.1% of CVEs· 85th percentile

Social Chatter

Signals from CVEs in this product scope (296 CVEs).

Media Mentions

Signals from CVEs in this product scope (296 CVEs).

Top CNAs Publishing CVEs For Big Ip Webaccelerator

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.4.827.520.9%01
9.4.727.520.9%01
9.4.627.520.9%01
9.4.527.520.9%01
9.4.427.520.9%01
9.4.327.520.9%01
9.4.227.520.9%01
9.4.127.520.9%01
9.4.027.520.9%01
9.2.215.93.3%00
21.0.0287.50.3%00
17.5.056.74.8%00
17.1.097.111.5%11
17.0.017.50.6%00
16.1.215.30.6%00
16.0.1.115.31.6%00
16.0.017.81.0%01
15.1.4.115.30.6%00
15.1.037.11.7%01
15.0.097.423.3%00