Tmos

Vendor:

First CVE: Nov 8, 1999 · Active for 26 years

7
Total CVEs
More Total CVEs than 83% of tracked products
1.4
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Tmos over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 8, 1999
26 years ago
Most Recent CVE
Jul 9, 2012
5,129 days ago

CVE Severity & Scoring

Tmos7 CVEs
All CVEs352,708 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown7 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown7 (100.0%)
User Interaction
None0 (0.0%)
Unknown7 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown7 (100.0%)

Top CVEs

Signals from CVEs in this product scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
F5 BIG-IP appliances 9.x before 9.4.8-HF5, 10.x before 10.2.4, 11.0.x before 11.0.0-HF2, and 11.1.x before 11.1.0-HF3, and Enterprise Manager before 2.1.0-HF2, 2.2.x before 2.2.0-H
Jul 9, 20127.878NOYES
Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connect
May 31, 20055.069NOYES
The management interface in F5 BIG-IP 9.4.3 allows remote authenticated users with Resource Manager privileges to inject arbitrary Perl code via unspecified configuration settings
Mar 16, 20099.024NONO
Multiple cross-site scripting (XSS) vulnerabilities in the Search function in the web management interface in F5 BIG-IP 9.4.3 allow remote attackers to inject arbitrary web script
Jan 15, 20084.322NOYES
Unknown vulnerability in F5 BIG-IP 9.0.2 through 9.1 allows attackers to "subvert the authentication of SSL transactions," via unknown attack vectors, possibly involving NATIVE cip
Jul 12, 20057.519NONO
bigconf.conf in F5 BIG/ip 2.1.2 and earlier allows remote attackers to read arbitrary files by specifying the target file in the "file" parameter.
Nov 8, 19995.017NONO
Cross-site scripting (XSS) vulnerability in the web management interface in F5 BIG-IP 9.4.3 allows remote attackers to inject arbitrary web script or HTML via (1) the name of a nod
Mar 25, 20084.314NONO

Exploit Exposure

Signals from CVEs in this product scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
14.3% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
42.9% of CVEs· 91st percentile

Social Chatter

Signals from CVEs in this product scope (7 CVEs).

Media Mentions

Signals from CVEs in this product scope (7 CVEs).

Top CNAs Publishing CVEs For Tmos

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.6.117.863.1%01
9.6.017.863.1%01
9.4.817.863.1%01
9.4.717.863.1%01
9.4.617.863.1%01
9.4.517.863.1%01
9.4.417.863.1%01
9.4.346.317.6%02
9.4.217.863.1%01
9.4.117.863.1%01
9.417.863.1%01
9.3.117.863.1%01
9.317.863.1%01
9.2.517.863.1%01
9.2.417.863.1%01
9.2.317.863.1%01
9.2.217.863.1%01
9.217.863.1%01
9.1.317.863.1%01
9.1.217.863.1%01