Tmos
Vendor:
First CVE: Nov 8, 1999 · Active for 26 years
7
Total CVEs
More Total CVEs than 83% of tracked products
1.4
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Tmos over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 8, 1999
26 years ago
Most Recent CVE
Jul 9, 2012
5,129 days ago
CVE Severity & Scoring
Tmos7 CVEs
57%
43%
All CVEs352,708 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown7 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown7 (100.0%)
User Interaction
None0 (0.0%)
Unknown7 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown7 (100.0%)
Top CVEs
Signals from CVEs in this product scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-1493HIGH F5 BIG-IP appliances 9.x before 9.4.8-HF5, 10.x before 10.2.4, 11.0.x before 11.0.0-HF2, and 11.1.x before 11.1.0-HF3, and Enterprise Manager before 2.1.0-HF2, 2.2.x before 2.2.0-H | Jul 9, 2012 | 7.8 | 78 | NO | YES |
CVE-2005-0356MEDIUM Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connect | May 31, 2005 | 5.0 | 69 | NO | YES |
CVE-2008-6474HIGH The management interface in F5 BIG-IP 9.4.3 allows remote authenticated users with Resource Manager privileges to inject arbitrary Perl code via unspecified configuration settings | Mar 16, 2009 | 9.0 | 24 | NO | NO |
CVE-2008-0265MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in the Search function in the web management interface in F5 BIG-IP 9.4.3 allow remote attackers to inject arbitrary web script | Jan 15, 2008 | 4.3 | 22 | NO | YES |
CVE-2005-2245HIGH Unknown vulnerability in F5 BIG-IP 9.0.2 through 9.1 allows attackers to "subvert the authentication of SSL transactions," via unknown attack vectors, possibly involving NATIVE cip | Jul 12, 2005 | 7.5 | 19 | NO | NO |
CVE-1999-1550MEDIUM bigconf.conf in F5 BIG/ip 2.1.2 and earlier allows remote attackers to read arbitrary files by specifying the target file in the "file" parameter. | Nov 8, 1999 | 5.0 | 17 | NO | NO |
CVE-2008-1503MEDIUM Cross-site scripting (XSS) vulnerability in the web management interface in F5 BIG-IP 9.4.3 allows remote attackers to inject arbitrary web script or HTML via (1) the name of a nod | Mar 25, 2008 | 4.3 | 14 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (7 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
14.3% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
42.9% of CVEs· 91st percentile
Social Chatter
Signals from CVEs in this product scope (7 CVEs).
Media Mentions
Signals from CVEs in this product scope (7 CVEs).
Top CNAs Publishing CVEs For Tmos
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.6.1 | 1 | 7.8 | 63.1% | 0 | 1 |
| 9.6.0 | 1 | 7.8 | 63.1% | 0 | 1 |
| 9.4.8 | 1 | 7.8 | 63.1% | 0 | 1 |
| 9.4.7 | 1 | 7.8 | 63.1% | 0 | 1 |
| 9.4.6 | 1 | 7.8 | 63.1% | 0 | 1 |
| 9.4.5 | 1 | 7.8 | 63.1% | 0 | 1 |
| 9.4.4 | 1 | 7.8 | 63.1% | 0 | 1 |
| 9.4.3 | 4 | 6.3 | 17.6% | 0 | 2 |
| 9.4.2 | 1 | 7.8 | 63.1% | 0 | 1 |
| 9.4.1 | 1 | 7.8 | 63.1% | 0 | 1 |
| 9.4 | 1 | 7.8 | 63.1% | 0 | 1 |
| 9.3.1 | 1 | 7.8 | 63.1% | 0 | 1 |
| 9.3 | 1 | 7.8 | 63.1% | 0 | 1 |
| 9.2.5 | 1 | 7.8 | 63.1% | 0 | 1 |
| 9.2.4 | 1 | 7.8 | 63.1% | 0 | 1 |
| 9.2.3 | 1 | 7.8 | 63.1% | 0 | 1 |
| 9.2.2 | 1 | 7.8 | 63.1% | 0 | 1 |
| 9.2 | 1 | 7.8 | 63.1% | 0 | 1 |
| 9.1.3 | 1 | 7.8 | 63.1% | 0 | 1 |
| 9.1.2 | 1 | 7.8 | 63.1% | 0 | 1 |