Big Iq Cloud

Vendor:

First CVE: Mar 11, 2014 · Active for 12 years

20
Total CVEs
More Total CVEs than 94% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 43% of tracked products
15.0%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Big Iq Cloud over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 11, 2014
12 years ago
Most Recent CVE
Jan 8, 2020
2,391 days ago

CVE Severity & Scoring

Big Iq Cloud20 CVEs
All CVEs352,719 CVEs
LowMediumHighCritical
Attack Vector
Local2 (10.0%)
Network9 (45.0%)
Unknown9 (45.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (40.0%)
High3 (15.0%)
Unknown9 (45.0%)
User Interaction
None11 (55.0%)
Unknown9 (45.0%)
Required0 (0.0%)
Privileges Required
Low1 (5.0%)
High1 (5.0%)
None9 (45.0%)
Unknown9 (45.0%)

Top CVEs

Signals from CVEs in this product scope (20 CVEs).

20 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a cra
Sep 24, 20149.899YESYES
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to wri
Sep 25, 20149.898YESYES
The iControl API in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.0 before 11.5.3 HF2 and 11.6.0 before 11.6.0 HF6, BIG-IP AAM 11.4.0 before 11.5.3 HF2 and
Dec 7, 20159.081NOYES
The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users
May 7, 20145.578YESYES
The rsync daemon in F5 BIG-IP 11.6 before 11.6.0, 11.5.1 before HF3, 11.5.0 before HF4, 11.4.1 before HF4, 11.4.0 before HF7, 11.3.0 before HF9, and 11.2.1 before HF11 and Enterpri
Oct 15, 20149.336NOYES
F5 BIG-IP LTM, Analytics, APM, ASM, and Link Controller 11.2.x before 11.2.1 HF16, 11.3.x, 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.6.1 HF1, and 12.x before 12.0.0 HF3; B
Sep 7, 20169.831NONO
An attacker may be able to cause a denial-of-service (DoS) attack against the sshd component in F5 BIG-IP, Enterprise Manager, BIG-IQ, and iWorkflow.
May 1, 20177.525NONO
The sctp_sf_do_5_1D_ce function in net/sctp/sm_statefuns.c in the Linux kernel through 3.13.6 does not validate certain auth_enable and auth_capable fields before making an sctp_sf
Mar 11, 20147.824NONO
The datastor kernel module in F5 BIG-IP Analytics, APM, ASM, Link Controller, and LTM 11.1.0 before 12.0.0, BIG-IP AAM 11.4.0 before 12.0.0, BIG-IP AFM, PEM 11.3.0 before 12.0.0, B
Nov 6, 20159.023NONO
racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a series of crafted UDP requests.
May 29, 20157.823NONO

Exploit Exposure

Signals from CVEs in this product scope (20 CVEs).

CISA KEV
3 CVEs
15.0% of CVEs· 98th percentile
Metasploit
2 CVEs
10.0% of CVEs· 97th percentile
Nuclei
1 CVE
5.0% of CVEs· 97th percentile
ExploitDB
5 CVEs
25.0% of CVEs· 90th percentile

Social Chatter

Signals from CVEs in this product scope (20 CVEs).

Media Mentions

Signals from CVEs in this product scope (20 CVEs).

Top CNAs Publishing CVEs For Big Iq Cloud

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.5.0117.38.0%01
4.4.0127.18.4%01
4.3.0107.510.5%02
4.2.0107.510.5%02
4.1.097.511.6%02
4.0.097.511.6%02