Big Ip Webaccelerator
Vendor:
First CVE: May 24, 2012 · Active for 14 years
296
Total CVEs
More Total CVEs than 100% of tracked products
19.7
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 42% of tracked products
2.4%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Big Ip Webaccelerator over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 24, 2012
14 years ago
Most Recent CVE
May 13, 2026
76 days ago
CVE Severity & Scoring
Big Ip Webaccelerator296 CVEs
41%
54%
All CVEs353,173 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local23 (7.8%)
Network248 (83.8%)
Unknown18 (6.1%)
Physical2 (0.7%)
Adjacent Network5 (1.7%)
Attack Complexity
Low244 (82.4%)
High34 (11.5%)
Unknown18 (6.1%)
User Interaction
None253 (85.5%)
Unknown18 (6.1%)
Required25 (8.4%)
Privileges Required
Low49 (16.6%)
High51 (17.2%)
None178 (60.1%)
Unknown18 (6.1%)
Top CVEs
Signals from CVEs in this product scope (296 CVEs).
296 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-6271CRITICAL GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a cra | Sep 24, 2014 | 9.8 | 99 | YES | YES |
CVE-2023-46747CRITICAL Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addre | Oct 26, 2023 | 9.8 | 98 | YES | YES |
CVE-2014-7169CRITICAL GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to wri | Sep 25, 2014 | 9.8 | 98 | YES | YES |
CVE-2023-44487HIGH The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through | Oct 10, 2023 | 7.5 | 97 | YES | YES |
CVE-2018-14634HIGH An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use thi | Sep 25, 2018 | 7.8 | 81 | YES | YES |
CVE-2015-3628HIGH The iControl API in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.0 before 11.5.3 HF2 and 11.6.0 before 11.6.0 HF6, BIG-IP AAM 11.4.0 before 11.5.3 HF2 and | Dec 7, 2015 | 9.0 | 81 | NO | YES |
CVE-2019-11477HIGH Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). | Jun 19, 2019 | 7.5 | 78 | NO | NO |
CVE-2014-0196MEDIUM The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users | May 7, 2014 | 5.5 | 78 | YES | YES |
CVE-2019-11478HIGH Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgme | Jun 19, 2019 | 7.5 | 76 | NO | NO |
CVE-2019-11479HIGH Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows a remote peer to fragment TCP resend queues significantly more than if a larger | Jun 19, 2019 | 7.5 | 75 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (296 CVEs).
CISA KEV
7 CVEs
2.4% of CVEs· 98th percentile
Metasploit
4 CVEs
1.4% of CVEs· 97th percentile
Nuclei
2 CVEs
0.7% of CVEs· 96th percentile
ExploitDB
12 CVEs
4.1% of CVEs· 85th percentile
Social Chatter
Signals from CVEs in this product scope (296 CVEs).
Media Mentions
Signals from CVEs in this product scope (296 CVEs).
Top CNAs Publishing CVEs For Big Ip Webaccelerator
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.4.8 | 2 | 7.5 | 20.9% | 0 | 1 |
| 9.4.7 | 2 | 7.5 | 20.9% | 0 | 1 |
| 9.4.6 | 2 | 7.5 | 20.9% | 0 | 1 |
| 9.4.5 | 2 | 7.5 | 20.9% | 0 | 1 |
| 9.4.4 | 2 | 7.5 | 20.9% | 0 | 1 |
| 9.4.3 | 2 | 7.5 | 20.9% | 0 | 1 |
| 9.4.2 | 2 | 7.5 | 20.9% | 0 | 1 |
| 9.4.1 | 2 | 7.5 | 20.9% | 0 | 1 |
| 9.4.0 | 2 | 7.5 | 20.9% | 0 | 1 |
| 9.2.2 | 1 | 5.9 | 3.3% | 0 | 0 |
| 21.0.0 | 28 | 7.5 | 0.3% | 0 | 0 |
| 17.5.0 | 5 | 6.7 | 4.8% | 0 | 0 |
| 17.1.0 | 9 | 7.1 | 11.5% | 1 | 1 |
| 17.0.0 | 1 | 7.5 | 0.6% | 0 | 0 |
| 16.1.2 | 1 | 5.3 | 0.6% | 0 | 0 |
| 16.0.1.1 | 1 | 5.3 | 1.6% | 0 | 0 |
| 16.0.0 | 1 | 7.8 | 1.0% | 0 | 1 |
| 15.1.4.1 | 1 | 5.3 | 0.6% | 0 | 0 |
| 15.1.0 | 3 | 7.1 | 1.7% | 0 | 1 |
| 15.0.0 | 9 | 7.4 | 23.3% | 0 | 0 |