Skip to main content

Vendor/product archive

f5 / big-iq_centralized_management CVEs

Beta · best-effort

83 CVEs tagged to f5 / big-iq_centralized_management7 Critical, 40 High, 36 Medium, 0 Low, 0 Unrated.

CVE-2026-20916

Published May 13, 2026

An authenticated iControl REST user with low privileges can create or modify arbitrary files through an undisclosed iControl REST endpoint on the BIG-IQ system.  Note: Software ve…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-47139

Published Oct 16, 2024

A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IQ Configuration utility that allows an attacker with the Administrator role to run Java…

CVSS 4.8 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2023-29240

Published May 3, 2023

An authenticated attacker granted a Viewer or Auditor role on a BIG-IQ can upload arbitrary files using an undisclosed iControl REST endpoint.  Note: Software versions which have…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-41622

Published Dec 7, 2022

In all versions,  BIG-IP and BIG-IQ are vulnerable to cross-site request forgery (CSRF) attacks through iControl SOAP.   Note: Software versions which have reached End of Techni…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5
Showing 1-25 of 83 CVEsPage 1 of 4