Refine your search

14 vulnerabilities found for NGINX by F5

CERTFR-2026-AVI-0120
Vulnerability from certfr_avis

De multiples vulnérabilités ont été découvertes dans les produits F5. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.

Solutions

Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

Impacted products
Vendor Product Description
F5 NGINX Nginx Open Source versions 1.29.x antérieures à 1.29.5
F5 BIG-IP BIG-IP versions 17.1.x antérieures à 17.1.3.1
F5 NGINX Nginx Plus versions R36 antérieures à R36 P1
F5 BIG-IP BIG-IP Container Ingress Services for Kubernetes and OpenShift versions 2.x antérieures à 2.20.2
F5 BIG-IP BIG-IP versions 17.5.x antérieures à 17.5.1.4
F5 BIG-IP APM Clients versions 7.2.x antérieures à 7.2.6.2
F5 BIG-IP BIG-IP versions 21.x antérieures à 21.0.0.1
F5 BIG-IP BIG-IP Advanced WAF/ASM versions 17.1.x antérieures à 17.1.3
F5 NGINX Nginx Open Source versions antérieures à 1.28.2
F5 NGINX Nginx Ingress Controller versions 3.x à 5.x sans la version corrective de Nginx plus ou Nginx Open Source
F5 NGINX Nginx Instance Manager versions 2.x sans la version corrective de Nginx Open Source
F5 NGINX Nginx Plus versions R32 antérieures à R32 P4
F5 NGINX Nginx Gateway Fabric versions 1.x et 2.x sans la version corrective de Nginx plus ou Nginx Open Source
F5 NGINX Nginx Plus versions R35 antérieures à R35 P1
References
Bulletin de sécurité F5 K000156643 2026-02-04 vendor-advisory
Bulletin de sécurité F5 K000157960 2026-02-04 vendor-advisory
Bulletin de sécurité F5 K000159824 2026-02-05 vendor-advisory
Bulletin de sécurité F5 K000158931 2026-02-04 vendor-advisory
Bulletin de sécurité F5 K000159076 2026-02-04 vendor-advisory
Bulletin de sécurité F5 K000156644 2026-02-04 vendor-advisory
Bulletin de sécurité F5 K000158072 2026-02-04 vendor-advisory

Show details on source website


{
  "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
  "affected_systems": [
    {
      "description": "Nginx Open Source versions 1.29.x ant\u00e9rieures \u00e0 1.29.5",
      "product": {
        "name": "NGINX",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP versions 17.1.x ant\u00e9rieures \u00e0 17.1.3.1",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "Nginx Plus versions R36 ant\u00e9rieures \u00e0 R36 P1",
      "product": {
        "name": "NGINX",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP Container Ingress Services for Kubernetes and OpenShift versions 2.x ant\u00e9rieures \u00e0 2.20.2",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP versions 17.5.x ant\u00e9rieures \u00e0 17.5.1.4",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "APM Clients versions 7.2.x ant\u00e9rieures \u00e0 7.2.6.2",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP versions 21.x ant\u00e9rieures \u00e0 21.0.0.1",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP Advanced WAF/ASM versions 17.1.x ant\u00e9rieures \u00e0 17.1.3",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "Nginx Open Source versions ant\u00e9rieures \u00e0 1.28.2",
      "product": {
        "name": "NGINX",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "Nginx Ingress Controller versions 3.x \u00e0 5.x sans la version corrective de Nginx plus ou Nginx Open Source",
      "product": {
        "name": "NGINX",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "Nginx Instance Manager versions 2.x sans la version corrective de Nginx Open Source",
      "product": {
        "name": "NGINX",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "Nginx Plus versions R32 ant\u00e9rieures \u00e0 R32 P4",
      "product": {
        "name": "NGINX",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "Nginx Gateway Fabric versions 1.x et 2.x sans la version corrective de Nginx plus ou Nginx Open Source",
      "product": {
        "name": "NGINX",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "Nginx Plus versions R35 ant\u00e9rieures \u00e0 R35 P1",
      "product": {
        "name": "NGINX",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    }
  ],
  "affected_systems_content": "",
  "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
  "cves": [
    {
      "name": "CVE-2026-1642",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1642"
    },
    {
      "name": "CVE-2026-22549",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22549"
    },
    {
      "name": "CVE-2026-20730",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20730"
    },
    {
      "name": "CVE-2026-22548",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22548"
    },
    {
      "name": "CVE-2026-20732",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20732"
    }
  ],
  "initial_release_date": "2026-02-05T00:00:00",
  "last_revision_date": "2026-02-05T00:00:00",
  "links": [],
  "reference": "CERTFR-2026-AVI-0120",
  "revisions": [
    {
      "description": "Version initiale",
      "revision_date": "2026-02-05T00:00:00.000000"
    }
  ],
  "risks": [
    {
      "description": "D\u00e9ni de service \u00e0 distance"
    },
    {
      "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
    },
    {
      "description": "Contournement de la politique de s\u00e9curit\u00e9"
    },
    {
      "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
    }
  ],
  "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits F5. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer un d\u00e9ni de service \u00e0 distance, une atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es et une atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es.",
  "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits F5",
  "vendor_advisories": [
    {
      "published_at": "2026-02-04",
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K000156643",
      "url": "https://my.f5.com/manage/s/article/K000156643"
    },
    {
      "published_at": "2026-02-04",
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K000157960",
      "url": "https://my.f5.com/manage/s/article/K000157960"
    },
    {
      "published_at": "2026-02-05",
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K000159824",
      "url": "https://my.f5.com/manage/s/article/K000159824"
    },
    {
      "published_at": "2026-02-04",
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K000158931",
      "url": "https://my.f5.com/manage/s/article/K000158931"
    },
    {
      "published_at": "2026-02-04",
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K000159076",
      "url": "https://my.f5.com/manage/s/article/K000159076"
    },
    {
      "published_at": "2026-02-04",
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K000156644",
      "url": "https://my.f5.com/manage/s/article/K000156644"
    },
    {
      "published_at": "2026-02-04",
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K000158072",
      "url": "https://my.f5.com/manage/s/article/K000158072"
    }
  ]
}

CERTFR-2025-AVI-0886
Vulnerability from certfr_avis

De multiples vulnérabilités ont été découvertes dans les produits F5. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, un déni de service à distance et une atteinte à la confidentialité des données.

Solutions

Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

Impacted products
Vendor Product Description
F5 BIG-IP Next BIG-IP Next pour Kubernetes versions 2.1.x antérieures à 2.1.0 EHF-2
F5 BIG-IP Next BIG-IP Next SPK versions 1.7.x antérieures à 1.7.15 EHF-2
F5 BIG-IP BIG-IP (tous les modules) versions 15.1.x antérieures à 15.1.10.8
F5 BIG-IP Next BIG-IP Next CNF versions 2.x antérieures à 2.1.0 EHF-1
F5 BIG-IP BIG-IP (tous les modules) versions 17.5.x antérieures à 17.5.1.3
F5 BIG-IP Next BIG-IP Next SPK versions 2.x antérieures à 2.1.0 EHF-1
F5 BIG-IP BIG-IP (tous les modules) versions 17.1.x antérieures à 17.1.3
F5 NGINX NGINX App Protect WAF versions antérieures à 4.7.0
F5 BIG-IP Next BIG-IP Next CNF versions 1.4.x antérieures à 1.4.0 EHF-3
F5 BIG-IP BIG-IP (tous les modules) versions 16.1.x antérieures à 16.1.6.1
References
Bulletin de sécurité F5 K000156572 2025-10-15 vendor-advisory

Show details on source website


{
  "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
  "affected_systems": [
    {
      "description": "BIG-IP Next pour Kubernetes versions 2.1.x ant\u00e9rieures \u00e0 2.1.0 EHF-2",
      "product": {
        "name": "BIG-IP Next",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP Next SPK versions 1.7.x ant\u00e9rieures \u00e0 1.7.15 EHF-2",
      "product": {
        "name": "BIG-IP Next",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP (tous les modules) versions 15.1.x ant\u00e9rieures \u00e0 15.1.10.8",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP Next CNF versions 2.x ant\u00e9rieures \u00e0 2.1.0 EHF-1",
      "product": {
        "name": "BIG-IP Next",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP (tous les modules) versions 17.5.x ant\u00e9rieures \u00e0 17.5.1.3",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP Next SPK versions 2.x ant\u00e9rieures \u00e0 2.1.0 EHF-1",
      "product": {
        "name": "BIG-IP Next",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP (tous les modules) versions 17.1.x ant\u00e9rieures \u00e0 17.1.3",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "NGINX App Protect WAF versions ant\u00e9rieures \u00e0 4.7.0",
      "product": {
        "name": "NGINX",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP Next CNF versions 1.4.x ant\u00e9rieures \u00e0 1.4.0 EHF-3",
      "product": {
        "name": "BIG-IP Next",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP (tous les modules) versions 16.1.x ant\u00e9rieures \u00e0 16.1.6.1",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    }
  ],
  "affected_systems_content": "",
  "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
  "cves": [
    {
      "name": "CVE-2025-48008",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-48008"
    },
    {
      "name": "CVE-2025-53521",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-53521"
    },
    {
      "name": "CVE-2025-54858",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-54858"
    },
    {
      "name": "CVE-2025-59478",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59478"
    },
    {
      "name": "CVE-2025-61990",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-61990"
    },
    {
      "name": "CVE-2025-55670",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-55670"
    },
    {
      "name": "CVE-2025-58153",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-58153"
    },
    {
      "name": "CVE-2025-58071",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-58071"
    },
    {
      "name": "CVE-2025-55036",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-55036"
    },
    {
      "name": "CVE-2025-53868",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-53868"
    },
    {
      "name": "CVE-2025-60015",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-60015"
    },
    {
      "name": "CVE-2025-59481",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59481"
    },
    {
      "name": "CVE-2025-54479",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-54479"
    },
    {
      "name": "CVE-2025-41430",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-41430"
    },
    {
      "name": "CVE-2025-59483",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59483"
    },
    {
      "name": "CVE-2025-59778",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59778"
    },
    {
      "name": "CVE-2025-59268",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59268"
    },
    {
      "name": "CVE-2025-53860",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-53860"
    },
    {
      "name": "CVE-2025-54805",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-54805"
    },
    {
      "name": "CVE-2025-61935",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-61935"
    },
    {
      "name": "CVE-2025-57780",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-57780"
    },
    {
      "name": "CVE-2025-61938",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-61938"
    },
    {
      "name": "CVE-2025-61951",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-61951"
    },
    {
      "name": "CVE-2025-59781",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59781"
    },
    {
      "name": "CVE-2025-53474",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-53474"
    },
    {
      "name": "CVE-2025-58096",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-58096"
    },
    {
      "name": "CVE-2025-61974",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-61974"
    },
    {
      "name": "CVE-2025-53856",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-53856"
    },
    {
      "name": "CVE-2025-58424",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-58424"
    },
    {
      "name": "CVE-2025-60013",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-60013"
    },
    {
      "name": "CVE-2025-60016",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-60016"
    },
    {
      "name": "CVE-2025-47150",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-47150"
    },
    {
      "name": "CVE-2025-58120",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-58120"
    },
    {
      "name": "CVE-2025-61958",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-61958"
    },
    {
      "name": "CVE-2025-59269",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59269"
    },
    {
      "name": "CVE-2025-54854",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-54854"
    },
    {
      "name": "CVE-2025-54755",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-54755"
    },
    {
      "name": "CVE-2025-61955",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-61955"
    },
    {
      "name": "CVE-2025-61960",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-61960"
    },
    {
      "name": "CVE-2025-58474",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-58474"
    },
    {
      "name": "CVE-2025-61933",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-61933"
    },
    {
      "name": "CVE-2025-47148",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-47148"
    },
    {
      "name": "CVE-2025-29481",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-29481"
    },
    {
      "name": "CVE-2025-46706",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-46706"
    },
    {
      "name": "CVE-2025-55669",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-55669"
    }
  ],
  "initial_release_date": "2025-10-16T00:00:00",
  "last_revision_date": "2025-10-16T00:00:00",
  "links": [],
  "reference": "CERTFR-2025-AVI-0886",
  "revisions": [
    {
      "description": "Version initiale",
      "revision_date": "2025-10-16T00:00:00.000000"
    }
  ],
  "risks": [
    {
      "description": "\u00c9l\u00e9vation de privil\u00e8ges"
    },
    {
      "description": "D\u00e9ni de service \u00e0 distance"
    },
    {
      "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
    },
    {
      "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
    },
    {
      "description": "Contournement de la politique de s\u00e9curit\u00e9"
    },
    {
      "description": "Injection de code indirecte \u00e0 distance (XSS)"
    },
    {
      "description": "Falsification de requ\u00eates c\u00f4t\u00e9 serveur (SSRF)"
    }
  ],
  "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits F5. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une \u00e9l\u00e9vation de privil\u00e8ges, un d\u00e9ni de service \u00e0 distance et une atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es.",
  "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits F5",
  "vendor_advisories": [
    {
      "published_at": "2025-10-15",
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K000156572",
      "url": "https://my.f5.com/manage/s/article/K000156572"
    }
  ]
}

CERTFR-2025-AVI-0710
Vulnerability from certfr_avis

De multiples vulnérabilités ont été découvertes dans les produits F5. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, un déni de service à distance et une atteinte à la confidentialité des données.

Solutions

Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

Impacted products
Vendor Product Description
F5 BIG-IP Next BIG-IP Next for Kubernetes versions 2.x antérieures à 2.0.0
F5 NGINX Plus NGINX Plus versions R33 antérieures à R33 P3
F5 BIG-IP BIG-IP (tous les modules) versions 17.5.x antérieures à Hotfix-BIGIP-17.5.1.0.80.7-ENG.iso3
F5 NGINX NGINX Open Source versions 0.7.22 à 1.29.0 antérieures à 1.29.1
F5 BIG-IP BIG-IP (tous les modules) versions 17.1.x antérieures à Hotfix-BIGIP-17.1.2.2.0.259.12-ENG.iso3
F5 BIG-IP Next BIG-IP Next for Kubernetes versions 2.0.0
F5 BIG-IP Next BIG-IP Next CNF versions 2.0.0 à 2.0.2 et 1.1.0 à 1.4.1
F5 BIG-IP Next BIG-IP Next (tous les modules) versions 20.x antérieures à 20.3.0
F5 BIG-IP Next BIG-IP Next (tous les modules) versions 20.3.0
F5 BIG-IP BIG-IP (APM) versions 17.1.x antérieures à 17.1.2.2
F5 BIG-IP BIG-IP (tous les modules) versions 16.1.0 à 16.1.5 antérieures à 16.1.6
F5 BIG-IP BIG-IP (tous les modules) versions 17.x antérieures à 17.1.0 - 17.1.2
F5 NGINX Plus NGINX Plus versions R34 antérieures à R34 P2
F5 NGINX Plus NGINX Plus versions antérieures à R35
F5 BIG-IP BIG-IP (tous les modules) versions 16.1.x antérieures à Hotfix-BIGIP-16.1.6.0.27.3-ENG.iso3
F5 NGINX Plus NGINX Plus versions antérieures à R32 P3
F5 BIG-IP Next BIG-IP Next SPK versions 2.0.0 à 2.0.2 et 1.7.0 à 1.9.2
F5 BIG-IP Next BIG-IP Next SPK versions 2.0.x antérieures à 2.0.2
F5 BIG-IP BIG-IP (tous les modules) versions 17.1.0 à 17.1.2 antérieures à 17.1.2.2
F5 BIG-IP BIG-IP (APM) versions 17.5.0 à 17.5.1, 17.1.0 à 17.1.2, 16.1.0 à 16.1.6 et 15.1.0 à 15.1.10
F5 BIG-IP Next BIG-IP Next CNF versions 2.x antérieures à 2.0.0 - 2.0.2
F5 BIG-IP BIG-IP (APM) versions 16.1.x antérieures à 16.1.6
References
Bulletin de sécurité F5 K000141436 2025-08-13 vendor-advisory
Bulletin de sécurité F5 K000152635 2025-08-13 vendor-advisory
Bulletin de sécurité F5 K000151546 2025-08-13 vendor-advisory
Bulletin de sécurité F5 K000152001 2025-08-13 vendor-advisory
Bulletin de sécurité F5 K000152049 2025-08-13 vendor-advisory
Bulletin de sécurité F5 K000151782 2025-08-13 vendor-advisory

Show details on source website


{
  "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
  "affected_systems": [
    {
      "description": "BIG-IP Next for Kubernetes versions 2.x ant\u00e9rieures \u00e0 2.0.0",
      "product": {
        "name": "BIG-IP Next",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "NGINX Plus versions R33 ant\u00e9rieures \u00e0 R33 P3",
      "product": {
        "name": "NGINX Plus",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP (tous les modules) versions 17.5.x ant\u00e9rieures \u00e0 Hotfix-BIGIP-17.5.1.0.80.7-ENG.iso3",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "NGINX Open Source versions 0.7.22 \u00e0 1.29.0 ant\u00e9rieures \u00e0 1.29.1",
      "product": {
        "name": "NGINX",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP (tous les modules) versions 17.1.x ant\u00e9rieures \u00e0 Hotfix-BIGIP-17.1.2.2.0.259.12-ENG.iso3",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP Next for Kubernetes versions 2.0.0",
      "product": {
        "name": "BIG-IP Next",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP Next CNF versions 2.0.0 \u00e0 2.0.2 et 1.1.0 \u00e0 1.4.1",
      "product": {
        "name": "BIG-IP Next",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP Next (tous les modules) versions 20.x ant\u00e9rieures \u00e0 20.3.0",
      "product": {
        "name": "BIG-IP Next",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP Next (tous les modules) versions 20.3.0",
      "product": {
        "name": "BIG-IP Next",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP (APM) versions 17.1.x ant\u00e9rieures \u00e0 17.1.2.2",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP (tous les modules) versions 16.1.0 \u00e0 16.1.5 ant\u00e9rieures \u00e0 16.1.6",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP (tous les modules) versions 17.x ant\u00e9rieures \u00e0 17.1.0 - 17.1.2",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "NGINX Plus versions R34 ant\u00e9rieures \u00e0 R34 P2",
      "product": {
        "name": "NGINX Plus",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "NGINX Plus versions ant\u00e9rieures \u00e0 R35",
      "product": {
        "name": "NGINX Plus",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP (tous les modules) versions 16.1.x ant\u00e9rieures \u00e0 Hotfix-BIGIP-16.1.6.0.27.3-ENG.iso3",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "NGINX Plus versions ant\u00e9rieures \u00e0 R32 P3",
      "product": {
        "name": "NGINX Plus",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP Next SPK versions 2.0.0 \u00e0 2.0.2 et 1.7.0 \u00e0 1.9.2",
      "product": {
        "name": "BIG-IP Next",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP Next SPK versions 2.0.x ant\u00e9rieures \u00e0 2.0.2",
      "product": {
        "name": "BIG-IP Next",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP (tous les modules) versions 17.1.0 \u00e0 17.1.2 ant\u00e9rieures \u00e0 17.1.2.2",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP (APM) versions 17.5.0 \u00e0 17.5.1, 17.1.0 \u00e0 17.1.2, 16.1.0 \u00e0 16.1.6 et 15.1.0 \u00e0 15.1.10",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP Next CNF versions 2.x ant\u00e9rieures \u00e0 2.0.0 - 2.0.2",
      "product": {
        "name": "BIG-IP Next",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP (APM) versions 16.1.x ant\u00e9rieures \u00e0 16.1.6",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    }
  ],
  "affected_systems_content": "",
  "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
  "cves": [
    {
      "name": "CVE-2025-53859",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-53859"
    },
    {
      "name": "CVE-2025-54500",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-54500"
    },
    {
      "name": "CVE-2025-54809",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-54809"
    },
    {
      "name": "CVE-2025-52585",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-52585"
    },
    {
      "name": "CVE-2025-48500",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-48500"
    },
    {
      "name": "CVE-2025-46405",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-46405"
    }
  ],
  "initial_release_date": "2025-08-19T00:00:00",
  "last_revision_date": "2025-08-19T00:00:00",
  "links": [],
  "reference": "CERTFR-2025-AVI-0710",
  "revisions": [
    {
      "description": "Version initiale",
      "revision_date": "2025-08-19T00:00:00.000000"
    }
  ],
  "risks": [
    {
      "description": "D\u00e9ni de service \u00e0 distance"
    },
    {
      "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
    },
    {
      "description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
    },
    {
      "description": "Contournement de la politique de s\u00e9curit\u00e9"
    },
    {
      "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
    },
    {
      "description": "\u00c9l\u00e9vation de privil\u00e8ges"
    }
  ],
  "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits F5. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une \u00e9l\u00e9vation de privil\u00e8ges, un d\u00e9ni de service \u00e0 distance et une atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es.",
  "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits F5",
  "vendor_advisories": [
    {
      "published_at": "2025-08-13",
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K000141436",
      "url": "https://my.f5.com/manage/s/article/K000141436"
    },
    {
      "published_at": "2025-08-13",
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K000152635",
      "url": "https://my.f5.com/manage/s/article/K000152635"
    },
    {
      "published_at": "2025-08-13",
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K000151546",
      "url": "https://my.f5.com/manage/s/article/K000151546"
    },
    {
      "published_at": "2025-08-13",
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K000152001",
      "url": "https://my.f5.com/manage/s/article/K000152001"
    },
    {
      "published_at": "2025-08-13",
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K000152049",
      "url": "https://my.f5.com/manage/s/article/K000152049"
    },
    {
      "published_at": "2025-08-13",
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K000151782",
      "url": "https://my.f5.com/manage/s/article/K000151782"
    }
  ]
}

CERTFR-2025-AVI-0099
Vulnerability from certfr_avis

De multiples vulnérabilités ont été découvertes dans les produits F5. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.

Solutions

Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

Impacted products
Vendor Product Description
F5 NGINX Plus NGINX Plus versions R28 à R33 antérieures à R32 P2 ou R33 P2
F5 BIG-IP BIG-IP versions 16.1.x antérieures à 16.1.5.2 sans les derniers correctifs de sécurité
F5 BIG-IP Next BIG-IP Next Central Manager versions 20.x antérieures à 20.3.0
F5 BIG-IP Next BIG-IP Next SPK versions 1.8.x à 1.9.x antérieures à 1.9.1
F5 BIG-IP BIG-IP versions 15.1.x antérieures à 15.1.10.6 sans les derniers correctifs de sécurité
F5 BIG-IP BIG-IP versions 17.1.x antérieures à 17.1.2.1
F5 BIG-IP Next BIG-IP Next SPK versions 1.7.x antérieures à 1.7.7
F5 NGINX NGINX Open Source versions 1.x antérieures à 1.26.3 ou 1.27.4
F5 BIG-IP Next BIG-IP Next CNF versions antérieures à 1.4.0
References
Bulletin de sécurité F5 K000149540 2025-02-05 vendor-advisory

Show details on source website


{
  "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
  "affected_systems": [
    {
      "description": "NGINX Plus versions R28 \u00e0 R33 ant\u00e9rieures \u00e0 R32 P2 ou R33 P2",
      "product": {
        "name": "NGINX Plus",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP versions 16.1.x ant\u00e9rieures \u00e0 16.1.5.2 sans les derniers correctifs de s\u00e9curit\u00e9",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP Next Central Manager versions 20.x ant\u00e9rieures \u00e0 20.3.0",
      "product": {
        "name": "BIG-IP Next",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP Next SPK versions 1.8.x \u00e0 1.9.x ant\u00e9rieures \u00e0 1.9.1",
      "product": {
        "name": "BIG-IP Next",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP versions 15.1.x ant\u00e9rieures \u00e0 15.1.10.6 sans les derniers correctifs de s\u00e9curit\u00e9",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP versions 17.1.x ant\u00e9rieures \u00e0 17.1.2.1",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP Next SPK versions 1.7.x ant\u00e9rieures \u00e0 1.7.7",
      "product": {
        "name": "BIG-IP Next",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "NGINX Open Source versions 1.x ant\u00e9rieures \u00e0 1.26.3 ou 1.27.4",
      "product": {
        "name": "NGINX",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP Next CNF versions ant\u00e9rieures \u00e0 1.4.0",
      "product": {
        "name": "BIG-IP Next",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    }
  ],
  "affected_systems_content": "",
  "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
  "cves": [
    {
      "name": "CVE-2025-23413",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-23413"
    },
    {
      "name": "CVE-2025-22891",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-22891"
    },
    {
      "name": "CVE-2025-24326",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-24326"
    },
    {
      "name": "CVE-2025-24320",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-24320"
    },
    {
      "name": "CVE-2025-20045",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-20045"
    },
    {
      "name": "CVE-2025-24497",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-24497"
    },
    {
      "name": "CVE-2025-20058",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-20058"
    },
    {
      "name": "CVE-2025-23239",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-23239"
    },
    {
      "name": "CVE-2025-23415",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-23415"
    },
    {
      "name": "CVE-2025-21087",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-21087"
    },
    {
      "name": "CVE-2025-24319",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-24319"
    },
    {
      "name": "CVE-2025-20029",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-20029"
    },
    {
      "name": "CVE-2025-21091",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-21091"
    },
    {
      "name": "CVE-2025-22846",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-22846"
    },
    {
      "name": "CVE-2025-23419",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-23419"
    },
    {
      "name": "CVE-2025-24312",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-24312"
    },
    {
      "name": "CVE-2025-23412",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-23412"
    }
  ],
  "initial_release_date": "2025-02-06T00:00:00",
  "last_revision_date": "2025-02-06T00:00:00",
  "links": [],
  "reference": "CERTFR-2025-AVI-0099",
  "revisions": [
    {
      "description": "Version initiale",
      "revision_date": "2025-02-06T00:00:00.000000"
    }
  ],
  "risks": [
    {
      "description": "D\u00e9ni de service \u00e0 distance"
    },
    {
      "description": "Injection de code indirecte \u00e0 distance (XSS)"
    },
    {
      "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
    },
    {
      "description": "Contournement de la politique de s\u00e9curit\u00e9"
    },
    {
      "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
    }
  ],
  "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits F5. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance, un d\u00e9ni de service \u00e0 distance et une atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es.",
  "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits F5",
  "vendor_advisories": [
    {
      "published_at": "2025-02-05",
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K000149540",
      "url": "https://my.f5.com/manage/s/article/K000149540"
    }
  ]
}

CERTFR-2024-AVI-0699
Vulnerability from certfr_avis

De multiples vulnérabilités ont été découvertes dans les produits F5. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et un contournement de la politique de sécurité.

Solutions

Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

Impacted products
Vendor Product Description
F5 BIG-IP BIG-IP (tous les modules) versions 15.x toutes versions pour les vulnérabilités CVE-2024-39778, CVE-2024-41727 et CVE-2024-41723
F5 BIG-IP BIG-IP (tous les modules) versions 17.1.x antérieures à 17.1.1
F5 BIG-IP BIG-IP (tous les modules) versions 16.1.x antérieures à 16.1.5
F5 NGINX NGINX Plus versions R32 antérieures à R32 P1
F5 BIG-IP Next BIG-IP Next SPK versions 1.7.0 à 1.8.2 antérieures à 1.9.0
F5 NGINX NGINX Open Source versions 1.5.13 à 1.26.1 antérieures à 1.26.2 et 1.27.1
F5 BIG-IP BIG-IP (tous les modules) versions 15.x antérieures à 15.1.10
F5 BIG-IP Next BIG-IP Next CNF versions 1.x antérieures à 1.2.0
F5 NGINX NGINX Plus versions R2x et R3x antérieures à R31 P3
F5 BIG-IP Next BIG-IP Next Central Manager versions 20.x antérieures à 20.2.1
References
Bulletin de sécurité F5 K000140108 2024-08-14 vendor-advisory
Bulletin de sécurité F5 K000140552 2024-08-14 vendor-advisory
Bulletin de sécurité F5 K000139938 2024-08-14 vendor-advisory
Bulletin de sécurité F5 K000138833 2024-08-14 vendor-advisory
Bulletin de sécurité F5 K05710614 2024-08-14 vendor-advisory
Bulletin de sécurité F5 K000140006 2024-08-14 vendor-advisory
Bulletin de sécurité F5 K000140111 2024-08-14 vendor-advisory
Bulletin de sécurité F5 K000140529 2024-08-14 vendor-advisory
Bulletin de sécurité F5 K10438187 2024-08-14 vendor-advisory
Bulletin de sécurité F5 K000138477 2024-08-14 vendor-advisory

Show details on source website


{
  "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
  "affected_systems": [
    {
      "description": "BIG-IP (tous les modules) versions 15.x toutes versions pour les vuln\u00e9rabilit\u00e9s CVE-2024-39778, CVE-2024-41727 et  CVE-2024-41723",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP (tous les modules) versions 17.1.x ant\u00e9rieures \u00e0 17.1.1",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP (tous les modules) versions 16.1.x ant\u00e9rieures \u00e0 16.1.5",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "NGINX Plus versions R32 ant\u00e9rieures \u00e0 R32 P1",
      "product": {
        "name": "NGINX",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP Next SPK versions 1.7.0 \u00e0 1.8.2 ant\u00e9rieures \u00e0 1.9.0",
      "product": {
        "name": "BIG-IP Next",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "NGINX Open Source versions 1.5.13 \u00e0 1.26.1 ant\u00e9rieures \u00e0 1.26.2 et 1.27.1",
      "product": {
        "name": "NGINX",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP (tous les modules) versions 15.x ant\u00e9rieures \u00e0 15.1.10",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP Next CNF versions 1.x ant\u00e9rieures \u00e0 1.2.0",
      "product": {
        "name": "BIG-IP Next",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "NGINX Plus versions R2x et R3x ant\u00e9rieures \u00e0 R31 P3",
      "product": {
        "name": "NGINX",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP Next Central Manager versions 20.x ant\u00e9rieures \u00e0 20.2.1",
      "product": {
        "name": "BIG-IP Next",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    }
  ],
  "affected_systems_content": "",
  "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
  "cves": [
    {
      "name": "CVE-2024-7347",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-7347"
    },
    {
      "name": "CVE-2024-41727",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-41727"
    },
    {
      "name": "CVE-2024-41719",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-41719"
    },
    {
      "name": "CVE-2024-39792",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-39792"
    },
    {
      "name": "CVE-2024-39778",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-39778"
    },
    {
      "name": "CVE-2024-37028",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-37028"
    },
    {
      "name": "CVE-2024-41723",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-41723"
    },
    {
      "name": "CVE-2024-39809",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-39809"
    },
    {
      "name": "CVE-2024-41164",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-41164"
    }
  ],
  "initial_release_date": "2024-08-19T00:00:00",
  "last_revision_date": "2024-08-19T00:00:00",
  "links": [],
  "reference": "CERTFR-2024-AVI-0699",
  "revisions": [
    {
      "description": "Version initiale",
      "revision_date": "2024-08-19T00:00:00.000000"
    }
  ],
  "risks": [
    {
      "description": "D\u00e9ni de service \u00e0 distance"
    },
    {
      "description": "Contournement de la politique de s\u00e9curit\u00e9"
    },
    {
      "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
    }
  ],
  "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits F5. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer un d\u00e9ni de service \u00e0 distance, une atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es et un contournement de la politique de s\u00e9curit\u00e9.",
  "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits F5 et Nginx",
  "vendor_advisories": [
    {
      "published_at": "2024-08-14",
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K000140108",
      "url": "https://my.f5.com/manage/s/article/K000140108"
    },
    {
      "published_at": "2024-08-14",
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K000140552",
      "url": "https://my.f5.com/manage/s/article/K000140552"
    },
    {
      "published_at": "2024-08-14",
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K000139938",
      "url": "https://my.f5.com/manage/s/article/K000139938"
    },
    {
      "published_at": "2024-08-14",
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K000138833",
      "url": "https://my.f5.com/manage/s/article/K000138833"
    },
    {
      "published_at": "2024-08-14",
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K05710614",
      "url": "https://my.f5.com/manage/s/article/K05710614"
    },
    {
      "published_at": "2024-08-14",
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K000140006",
      "url": "https://my.f5.com/manage/s/article/K000140006"
    },
    {
      "published_at": "2024-08-14",
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K000140111",
      "url": "https://my.f5.com/manage/s/article/K000140111"
    },
    {
      "published_at": "2024-08-14",
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K000140529",
      "url": "https://my.f5.com/manage/s/article/K000140529"
    },
    {
      "published_at": "2024-08-14",
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K10438187",
      "url": "https://my.f5.com/manage/s/article/K10438187"
    },
    {
      "published_at": "2024-08-14",
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K000138477",
      "url": "https://my.f5.com/manage/s/article/K000138477"
    }
  ]
}

CERTFR-2024-AVI-0377
Vulnerability from certfr_avis

De multiples vulnérabilités ont été découvertes dans les produits F5. Certaines d'entre elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur, une exécution de code arbitraire à distance et un déni de service à distance.

Solution

Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

None
Impacted products
Vendor Product Description
F5 BIG-IP Next BIG-IP Next Central Manager versions 20.0.x antérieures à 20.2.0
F5 BIG-IP BIG-IP AFM versions 17.0.x antérieures à 17.1.1
F5 BIG-IP BIG-IP AFM versions antérieures à 16.1.4
F5 BIG-IP BIG-IP APM versions 16.1.x antérieures à 16.1.4.2
F5 N/A APM Clients versions postérieures à 7.2.3 et antérieures à 7.2.4.4
F5 BIG-IP Next BIG-IP Next CNF versions antérieures à 1.3.0
F5 BIG-IP BIG-IP "tous les autres modules" versions 15.1.x antérieures à 15.1.5.1
F5 BIG-IP BIG-IP "tous les autres modules" versions 16.1.x antérieures à 16.1.2.2
F5 BIG-IP BIG-IP versions 15.1.x antérieures à 15.1.10.4
F5 BIG-IP BIG-IP Advanced WAF/ASM versions 17.1.x antérieures à 17.1.3
F5 BIG-IP BIG-IP APM versions 15.1.x antérieures à 15.1.10.3
F5 BIG-IP BIG-IP APM versions 17.1.x antérieures à 17.1.1
F5 BIG-IP BIG-IP Advanced WAF/ASM versions 15.1.x antérieures à 15.1.10.4
F5 BIG-IP BIG-IP versions 16.1.x antérieures à 16.1.4.3
F5 BIG-IP Next BIG-IP Next SPK versions antérieures à 1.7.0
F5 BIG-IP BIG-IP Advanced WAF/ASM versions 16.1.x antérieures à 16.1.4.3
F5 BIG-IP Next BIG-IP Next WAF versions 20.0.x antérieures à 20.2.0
F5 BIG-IP BIG-IP AFM versions 15.1.x antérieures à 15.1.10.4
F5 NGINX NGINX App Protect WAF versions antérieures à 4.8.1
F5 BIG-IP BIG-IP versions 17.1.x antérieures à 17.1.3
References

Show details on source website


{
  "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
  "affected_systems": [
    {
      "description": "BIG-IP Next Central Manager versions 20.0.x ant\u00e9rieures \u00e0 20.2.0",
      "product": {
        "name": "BIG-IP Next",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP AFM versions 17.0.x ant\u00e9rieures \u00e0 17.1.1",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP AFM versions ant\u00e9rieures \u00e0 16.1.4",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP APM versions 16.1.x ant\u00e9rieures \u00e0 16.1.4.2",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "APM Clients versions post\u00e9rieures \u00e0 7.2.3 et ant\u00e9rieures \u00e0 7.2.4.4",
      "product": {
        "name": "N/A",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP Next CNF versions ant\u00e9rieures \u00e0 1.3.0",
      "product": {
        "name": "BIG-IP Next",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP \"tous les autres modules\" versions 15.1.x ant\u00e9rieures \u00e0 15.1.5.1",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP \"tous les autres modules\" versions 16.1.x ant\u00e9rieures \u00e0 16.1.2.2",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP versions 15.1.x ant\u00e9rieures \u00e0 15.1.10.4",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP Advanced WAF/ASM versions 17.1.x ant\u00e9rieures \u00e0 17.1.3",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP APM versions 15.1.x ant\u00e9rieures \u00e0 15.1.10.3",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP APM versions 17.1.x ant\u00e9rieures \u00e0 17.1.1",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP Advanced WAF/ASM versions 15.1.x ant\u00e9rieures \u00e0 15.1.10.4",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP versions 16.1.x ant\u00e9rieures \u00e0 16.1.4.3",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP Next SPK versions ant\u00e9rieures \u00e0 1.7.0",
      "product": {
        "name": "BIG-IP Next",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP Advanced WAF/ASM versions 16.1.x ant\u00e9rieures \u00e0 16.1.4.3",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP Next WAF versions 20.0.x ant\u00e9rieures \u00e0 20.2.0",
      "product": {
        "name": "BIG-IP Next",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP AFM versions 15.1.x ant\u00e9rieures \u00e0 15.1.10.4",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "NGINX App Protect WAF versions ant\u00e9rieures \u00e0 4.8.1",
      "product": {
        "name": "NGINX",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP versions 17.1.x ant\u00e9rieures \u00e0 17.1.3",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    }
  ],
  "affected_systems_content": null,
  "content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
  "cves": [
    {
      "name": "CVE-2024-28889",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-28889"
    },
    {
      "name": "CVE-2024-33612",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-33612"
    },
    {
      "name": "CVE-2024-27202",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-27202"
    },
    {
      "name": "CVE-2024-21793",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-21793"
    },
    {
      "name": "CVE-2024-31156",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-31156"
    },
    {
      "name": "CVE-2024-32049",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-32049"
    },
    {
      "name": "CVE-2024-32761",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-32761"
    },
    {
      "name": "CVE-2024-28883",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-28883"
    },
    {
      "name": "CVE-2024-28132",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-28132"
    },
    {
      "name": "CVE-2024-33604",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-33604"
    },
    {
      "name": "CVE-2024-25560",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-25560"
    },
    {
      "name": "CVE-2024-26026",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-26026"
    },
    {
      "name": "CVE-2024-33608",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-33608"
    }
  ],
  "initial_release_date": "2024-05-10T00:00:00",
  "last_revision_date": "2024-05-10T00:00:00",
  "links": [],
  "reference": "CERTFR-2024-AVI-0377",
  "revisions": [
    {
      "description": "Version initiale",
      "revision_date": "2024-05-10T00:00:00.000000"
    }
  ],
  "risks": [
    {
      "description": "D\u00e9ni de service \u00e0 distance"
    },
    {
      "description": "Injection de code indirecte \u00e0 distance (XSS)"
    },
    {
      "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
    },
    {
      "description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
    },
    {
      "description": "Contournement de la politique de s\u00e9curit\u00e9"
    },
    {
      "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
    },
    {
      "description": "\u00c9l\u00e9vation de privil\u00e8ges"
    }
  ],
  "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits F5.\nCertaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer un\nprobl\u00e8me de s\u00e9curit\u00e9 non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur, une ex\u00e9cution de code\narbitraire \u00e0 distance et un d\u00e9ni de service \u00e0 distance.\n",
  "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits F5",
  "vendor_advisories": [
    {
      "published_at": null,
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K000139404 du 08 mai 2024",
      "url": "https://my.f5.com/manage/s/article/K000139404"
    }
  ]
}

CERTFR-2024-AVI-0137
Vulnerability from certfr_avis

De multiples vulnérabilités ont été découvertes dans les produits F5. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et un contournement de la politique de sécurité.

Solution

Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

None
Impacted products
Vendor Product Description
F5 NGINX Plus NGINX Plus versions R30 antérieures à R30 P2
F5 BIG-IP Next BIG-IP Next SPK versions 1.x.x postérieures à 1.5.0 et antérieures à 1.8.1
F5 BIG-IP BIG-IP versions 16.1.x antérieures à 16.1.4.2
F5 NGINX NGINX Open Source 1.25.x antérieures à 1.25.4
F5 BIG-IP BIG-IP versions 17.1.x antérieures à 17.1.1
F5 BIG-IP Next BIG-IP Next CNF versions 1.x.x postérieures à 1.1.0 et antérieures à 1.2.0
F5 BIG-IP BIG-IP versions 15.1.x antérieures à 15.1.10.3
F5 NGINX Plus NGINX Plus versions R31 antérieures à R31 P1
References

Show details on source website


{
  "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
  "affected_systems": [
    {
      "description": "NGINX Plus versions R30 ant\u00e9rieures \u00e0 R30 P2",
      "product": {
        "name": "NGINX Plus",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP Next SPK versions 1.x.x post\u00e9rieures \u00e0 1.5.0 et ant\u00e9rieures \u00e0 1.8.1",
      "product": {
        "name": "BIG-IP Next",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP versions 16.1.x ant\u00e9rieures \u00e0 16.1.4.2",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "NGINX Open Source 1.25.x ant\u00e9rieures \u00e0 1.25.4",
      "product": {
        "name": "NGINX",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP versions 17.1.x ant\u00e9rieures \u00e0 17.1.1",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP Next CNF versions 1.x.x post\u00e9rieures \u00e0 1.1.0 et ant\u00e9rieures \u00e0 1.2.0",
      "product": {
        "name": "BIG-IP Next",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP versions 15.1.x ant\u00e9rieures \u00e0 15.1.10.3",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "NGINX Plus versions R31 ant\u00e9rieures \u00e0 R31 P1",
      "product": {
        "name": "NGINX Plus",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    }
  ],
  "affected_systems_content": null,
  "content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
  "cves": [
    {
      "name": "CVE-2024-24989",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-24989"
    },
    {
      "name": "CVE-2024-21849",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-21849"
    },
    {
      "name": "CVE-2024-24775",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-24775"
    },
    {
      "name": "CVE-2024-23979",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-23979"
    },
    {
      "name": "CVE-2024-21782",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-21782"
    },
    {
      "name": "CVE-2024-21771",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-21771"
    },
    {
      "name": "CVE-2024-23805",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-23805"
    },
    {
      "name": "CVE-2024-21763",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-21763"
    },
    {
      "name": "CVE-2024-21789",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-21789"
    },
    {
      "name": "CVE-2024-22093",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-22093"
    },
    {
      "name": "CVE-2024-23603",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-23603"
    },
    {
      "name": "CVE-2024-23982",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-23982"
    },
    {
      "name": "CVE-2024-23314",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-23314"
    },
    {
      "name": "CVE-2024-22389",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-22389"
    },
    {
      "name": "CVE-2024-23308",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-23308"
    },
    {
      "name": "CVE-2024-23607",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-23607"
    },
    {
      "name": "CVE-2024-23306",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-23306"
    },
    {
      "name": "CVE-2024-24990",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-24990"
    }
  ],
  "initial_release_date": "2024-02-15T00:00:00",
  "last_revision_date": "2024-02-15T00:00:00",
  "links": [],
  "reference": "CERTFR-2024-AVI-0137",
  "revisions": [
    {
      "description": "Version initiale",
      "revision_date": "2024-02-15T00:00:00.000000"
    }
  ],
  "risks": [
    {
      "description": "D\u00e9ni de service \u00e0 distance"
    },
    {
      "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
    },
    {
      "description": "Contournement de la politique de s\u00e9curit\u00e9"
    },
    {
      "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
    }
  ],
  "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits F5.\nCertaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une\nex\u00e9cution de code arbitraire \u00e0 distance, un d\u00e9ni de service \u00e0 distance\net un contournement de la politique de s\u00e9curit\u00e9.\n",
  "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits F5",
  "vendor_advisories": [
    {
      "published_at": null,
      "title": "Bulletin de s\u00e9curit\u00e9 F5 du 14 f\u00e9vrier 2024",
      "url": "https://my.f5.com/manage/s/article/K000138353"
    }
  ]
}

CERTFR-2023-AVI-0837
Vulnerability from certfr_avis

De multiples vulnérabilités ont été découvertes dans les produits F5. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et un contournement de la politique de sécurité.

Solution

Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

None
Impacted products
Vendor Product Description
F5 NGINX NGINX OSS versions 1.9.5 à 1.25.2
F5 BIG-IP BIG-IP (tous modules) versions 16.1.x antérieures à 16.1.4.1 avec le correctif de sécurité Hotfix-BIGIP-16.1.4.1.0.13.5-ENG
F5 BIG-IQ BIG-IQ Centralized Management versions 8.0.0 à 8.3.0 antérieures à 8.3.0 avec le correctif Hotfix-BIG-IQ-8.3.0.0.12.118-ENG
F5 BIG-IP Next BIG-IP Next SPK versions 1.5.0 à 1.8.2
F5 BIG-IP BIG-IP (APM) versions 16.1.0 à 16.1.3 antérieures à 16.1.4
F5 NGINX Ingress Controller NGINX Ingress Controller versions 3.0.0 à 3.3.0
F5 BIG-IP BIG-IP (Advanced WAF/ASM) versions 16.1.x antérieures à 16.1.4
F5 NGINX Plus NGINX Plus verions R25 à R30 antérieures à R30 P1
F5 BIG-IP BIG-IP (DNS, LTM avec le license DNS Services activée) versions 13.1.x, 14.1.x, 15.1.x antérieures à 15.1.9
F5 NGINX Ingress Controller NGINX Ingress Controller versions 2.0.0 à 2.4.2
F5 BIG-IP BIG-IP (DNS, LTM avec le license DNS Services activée) versions 16.1.x antérieures à 16.1.4
F5 NGINX Ingress Controller NGINX Ingress Controller versions 1.12.2 à 1.12.5
F5 BIG-IP Next BIG-IP Next CNF versions 1.1.0 à 1.1.1
F5 NGINX NGINX App Protect WAF versions 3.3.0 à 3.12.2 et 4.x antérieures à 4.2.0
F5 BIG-IP BIG-IP (Advanced WAF/ASM) versions 13.1.x, 14.1.x, 15.1.x antérieures à 15.1.9
F5 N/A APM Clients versions 7.2.3.x, 7.2.4.x antérieures à 7.2.4.5
F5 BIG-IP Next BIG-IP Next (tous modules) version 20.0.1
F5 BIG-IP BIG-IP (tous modules) versions 13.1.x, 14.1.x, 15.1.x antérieures à 15.1.10.2
F5 BIG-IP BIG-IP (tous modules) versions 17.1.x antérieures à 17.1.0.3 avec le correctif de sécurité Hotfix-BIGIP-17.1.0.3.0.23.4-ENG
F5 BIG-IP BIG-IP (APM) versions 14.1.x, 15.1.x antérieures à 15.1.9
References

Show details on source website


{
  "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
  "affected_systems": [
    {
      "description": "NGINX OSS versions 1.9.5 \u00e0 1.25.2",
      "product": {
        "name": "NGINX",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP (tous modules) versions 16.1.x ant\u00e9rieures \u00e0 16.1.4.1 avec le correctif de s\u00e9curit\u00e9 Hotfix-BIGIP-16.1.4.1.0.13.5-ENG",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IQ Centralized Management versions 8.0.0 \u00e0 8.3.0 ant\u00e9rieures \u00e0 8.3.0 avec le correctif Hotfix-BIG-IQ-8.3.0.0.12.118-ENG",
      "product": {
        "name": "BIG-IQ",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP Next SPK versions 1.5.0 \u00e0 1.8.2",
      "product": {
        "name": "BIG-IP Next",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP (APM) versions 16.1.0 \u00e0 16.1.3 ant\u00e9rieures \u00e0 16.1.4",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "NGINX Ingress Controller versions 3.0.0 \u00e0 3.3.0",
      "product": {
        "name": "NGINX Ingress Controller",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP (Advanced WAF/ASM) versions 16.1.x ant\u00e9rieures \u00e0 16.1.4",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "NGINX Plus verions R25 \u00e0 R30 ant\u00e9rieures \u00e0 R30 P1",
      "product": {
        "name": "NGINX Plus",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP (DNS, LTM avec le license DNS Services activ\u00e9e) versions 13.1.x, 14.1.x, 15.1.x ant\u00e9rieures \u00e0 15.1.9",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "NGINX Ingress Controller versions 2.0.0 \u00e0 2.4.2",
      "product": {
        "name": "NGINX Ingress Controller",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP (DNS, LTM avec le license DNS Services activ\u00e9e) versions 16.1.x ant\u00e9rieures \u00e0 16.1.4",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "NGINX Ingress Controller versions 1.12.2 \u00e0 1.12.5",
      "product": {
        "name": "NGINX Ingress Controller",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP Next CNF versions 1.1.0 \u00e0 1.1.1",
      "product": {
        "name": "BIG-IP Next",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "NGINX App Protect WAF versions 3.3.0 \u00e0 3.12.2 et 4.x ant\u00e9rieures \u00e0 4.2.0",
      "product": {
        "name": "NGINX",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP (Advanced WAF/ASM) versions 13.1.x, 14.1.x, 15.1.x ant\u00e9rieures \u00e0 15.1.9",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "APM Clients versions 7.2.3.x, 7.2.4.x ant\u00e9rieures \u00e0 7.2.4.5",
      "product": {
        "name": "N/A",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP Next (tous modules) version 20.0.1",
      "product": {
        "name": "BIG-IP Next",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP (tous modules) versions 13.1.x, 14.1.x, 15.1.x ant\u00e9rieures \u00e0 15.1.10.2",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP (tous modules) versions 17.1.x ant\u00e9rieures \u00e0 17.1.0.3 avec le correctif de s\u00e9curit\u00e9 Hotfix-BIGIP-17.1.0.3.0.23.4-ENG",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP (APM) versions 14.1.x, 15.1.x ant\u00e9rieures \u00e0 15.1.9",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    }
  ],
  "affected_systems_content": null,
  "content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
  "cves": [
    {
      "name": "CVE-2023-40542",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-40542"
    },
    {
      "name": "CVE-2023-5450",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-5450"
    },
    {
      "name": "CVE-2023-41373",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-41373"
    },
    {
      "name": "CVE-2023-43746",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-43746"
    },
    {
      "name": "CVE-2023-40537",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-40537"
    },
    {
      "name": "CVE-2023-44487",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-44487"
    },
    {
      "name": "CVE-2023-41085",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-41085"
    },
    {
      "name": "CVE-2023-41253",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-41253"
    },
    {
      "name": "CVE-2023-42768",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-42768"
    },
    {
      "name": "CVE-2023-43611",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-43611"
    },
    {
      "name": "CVE-2023-45226",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-45226"
    },
    {
      "name": "CVE-2023-45219",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-45219"
    },
    {
      "name": "CVE-2023-41964",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-41964"
    },
    {
      "name": "CVE-2023-39447",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-39447"
    },
    {
      "name": "CVE-2023-40534",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-40534"
    },
    {
      "name": "CVE-2023-43485",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-43485"
    }
  ],
  "initial_release_date": "2023-10-12T00:00:00",
  "last_revision_date": "2023-10-12T00:00:00",
  "links": [],
  "reference": "CERTFR-2023-AVI-0837",
  "revisions": [
    {
      "description": "Version initiale",
      "revision_date": "2023-10-12T00:00:00.000000"
    }
  ],
  "risks": [
    {
      "description": "D\u00e9ni de service \u00e0 distance"
    },
    {
      "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
    },
    {
      "description": "Contournement de la politique de s\u00e9curit\u00e9"
    },
    {
      "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
    },
    {
      "description": "\u00c9l\u00e9vation de privil\u00e8ges"
    }
  ],
  "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits F5.\nCertaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une\nex\u00e9cution de code arbitraire \u00e0 distance, un d\u00e9ni de service \u00e0 distance\net un contournement de la politique de s\u00e9curit\u00e9.\n",
  "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits F5",
  "vendor_advisories": [
    {
      "published_at": null,
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K000137053 du 10 octobre 2023",
      "url": "https://my.f5.com/manage/s/article/K000137053"
    }
  ]
}

CERTFR-2022-AVI-937
Vulnerability from certfr_avis

De multiples vulnérabilités ont été découvertes dans les produits F5. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à l'intégrité des données.

Solution

Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

None
Impacted products
Vendor Product Description
F5 BIG-IP BIG-IP (all modules) versions 14.1.x antérieures à 14.1.5.2
F5 NGINX Plus NGINX Plus R26 P1 ou R27 P1
F5 BIG-IP BIG-IP (all modules) versions 17.0.x antérieures à 17.0.0.1
F5 NGINX Ingress Controller NGINX Ingress Controller toutes versions
F5 BIG-IP BIG-IP (all modules) versions 16.1.x antérieures à 16.1.3.2
F5 NGINX NGINX App Protect WAF versions antérieures à 3.12
F5 BIG-IP BIG-IP (all modules) versions 15.1.x antérieures à 15.1.7
F5 NGINX NGINX Open Source versions 1.22.x antérieures à 1.22.1
F5 BIG-IP BIG-IP (all modules) versions 13.1.x antérieures à 13.1.5.1
F5 NGINX NGINX Open Source versions 1.23.x antérieures à 1.23.2
F5 NGINX NGINX Open Source Subscription R1 P1 ou R2 P1

Show details on source website


{
  "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
  "affected_systems": [
    {
      "description": "BIG-IP (all modules) versions 14.1.x ant\u00e9rieures \u00e0 14.1.5.2",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "NGINX Plus R26 P1 ou R27 P1",
      "product": {
        "name": "NGINX Plus",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP (all modules) versions 17.0.x ant\u00e9rieures \u00e0 17.0.0.1",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "NGINX Ingress Controller toutes versions",
      "product": {
        "name": "NGINX Ingress Controller",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP (all modules) versions 16.1.x ant\u00e9rieures \u00e0 16.1.3.2",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "NGINX App Protect WAF versions ant\u00e9rieures \u00e0 3.12",
      "product": {
        "name": "NGINX",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP (all modules) versions 15.1.x ant\u00e9rieures \u00e0 15.1.7",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "NGINX Open Source versions 1.22.x ant\u00e9rieures \u00e0 1.22.1",
      "product": {
        "name": "NGINX",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "BIG-IP (all modules) versions 13.1.x ant\u00e9rieures \u00e0 13.1.5.1",
      "product": {
        "name": "BIG-IP",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "NGINX Open Source versions 1.23.x ant\u00e9rieures \u00e0 1.23.2",
      "product": {
        "name": "NGINX",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "NGINX Open Source Subscription R1 P1 ou R2 P1",
      "product": {
        "name": "NGINX",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    }
  ],
  "affected_systems_content": null,
  "content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
  "cves": [
    {
      "name": "CVE-2022-36795",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-36795"
    },
    {
      "name": "CVE-2022-41770",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-41770"
    },
    {
      "name": "CVE-2022-41787",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-41787"
    },
    {
      "name": "CVE-2022-41691",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-41691"
    },
    {
      "name": "CVE-2022-41813",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-41813"
    },
    {
      "name": "CVE-2022-41694",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-41694"
    },
    {
      "name": "CVE-2022-41741",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-41741"
    },
    {
      "name": "CVE-2022-41742",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-41742"
    },
    {
      "name": "CVE-2022-41836",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-41836"
    },
    {
      "name": "CVE-2022-41624",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-41624"
    },
    {
      "name": "CVE-2022-41833",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-41833"
    },
    {
      "name": "CVE-2022-41806",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-41806"
    },
    {
      "name": "CVE-2022-41617",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-41617"
    },
    {
      "name": "CVE-2022-41832",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-41832"
    },
    {
      "name": "CVE-2022-41983",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-41983"
    },
    {
      "name": "CVE-2022-41743",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-41743"
    }
  ],
  "initial_release_date": "2022-10-20T00:00:00",
  "last_revision_date": "2022-10-20T00:00:00",
  "links": [
    {
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K11830089 du 19 octobre 2022",
      "url": "https://support.f5.com/csp/article/K11830089"
    },
    {
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K02694732 du 19 octobre 2022",
      "url": "https://support.f5.com/csp/article/K02694732"
    },
    {
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K30425568 du 19 octobre 2022",
      "url": "https://support.f5.com/csp/article/K30425568"
    },
    {
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K28112382 du 19 octobre 2022",
      "url": "https://support.f5.com/csp/article/K28112382"
    },
    {
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K70569537 du 19 octobre 2022",
      "url": "https://support.f5.com/csp/article/K70569537"
    },
    {
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K01112063 du 19 octobre 2022",
      "url": "https://support.f5.com/csp/article/K01112063"
    },
    {
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K81926432 du 19 octobre 2022",
      "url": "https://support.f5.com/csp/article/K81926432"
    },
    {
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K27155546 du 19 octobre 2022",
      "url": "https://support.f5.com/csp/article/K27155546"
    },
    {
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K10347453 du 19 octobre 2022",
      "url": "https://support.f5.com/csp/article/K10347453"
    },
    {
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K49237345 du 19 octobre 2022",
      "url": "https://support.f5.com/csp/article/K49237345"
    },
    {
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K22505850 du 19 octobre 2022",
      "url": "https://support.f5.com/csp/article/K22505850"
    },
    {
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K24823443 du 19 octobre 2022",
      "url": "https://support.f5.com/csp/article/K24823443"
    },
    {
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K47204506 du 19 octobre 2022",
      "url": "https://support.f5.com/csp/article/K47204506"
    },
    {
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K31523465 du 19 octobre 2022",
      "url": "https://support.f5.com/csp/article/K31523465"
    },
    {
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K52494562 du 19 octobre 2022",
      "url": "https://support.f5.com/csp/article/K52494562"
    },
    {
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K43024307 du 19 octobre 2022",
      "url": "https://support.f5.com/csp/article/K43024307"
    },
    {
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K93723284 du 19 octobre 2022",
      "url": "https://support.f5.com/csp/article/K93723284"
    },
    {
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K00721320 du 19 octobre 2022",
      "url": "https://support.f5.com/csp/article/K00721320"
    },
    {
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K04712583 du 19 octobre 2022",
      "url": "https://support.f5.com/csp/article/K04712583"
    }
  ],
  "reference": "CERTFR-2022-AVI-937",
  "revisions": [
    {
      "description": "Version initiale",
      "revision_date": "2022-10-20T00:00:00.000000"
    }
  ],
  "risks": [
    {
      "description": "D\u00e9ni de service \u00e0 distance"
    },
    {
      "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
    },
    {
      "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
    },
    {
      "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
    }
  ],
  "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits F5.\nCertaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une\nex\u00e9cution de code arbitraire \u00e0 distance, un d\u00e9ni de service \u00e0 distance\net une atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es.\n",
  "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits F5",
  "vendor_advisories": [
    {
      "published_at": null,
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K76934290 du 19 octobre 2022",
      "url": "https://support.f5.com/csp/article/K76934290"
    }
  ]
}

CERTFR-2022-AVI-792
Vulnerability from certfr_avis

De multiples vulnérabilités ont été découvertes dans les produits F5. Elles permettent à un attaquant de provoquer une exécution de code arbitraire, un déni de service à distance et une élévation de privilèges.

Solution

Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

None
Impacted products
Vendor Product Description
F5 NGINX NGINX ModSecurity WAF versions R25 antérieures à R25+1.0.2-3
F5 NGINX NGINX ModSecurity WAF versions R24 antérieures à R24+1.0.2-2
References

Show details on source website


{
  "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
  "affected_systems": [
    {
      "description": "NGINX ModSecurity WAF versions R25 ant\u00e9rieures \u00e0 R25+1.0.2-3",
      "product": {
        "name": "NGINX",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "NGINX ModSecurity WAF versions R24 ant\u00e9rieures \u00e0 R24+1.0.2-2",
      "product": {
        "name": "NGINX",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    }
  ],
  "affected_systems_content": null,
  "content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
  "cves": [
    {
      "name": "CVE-2021-42717",
      "url": "https://www.cve.org/CVERecord?id=CVE-2021-42717"
    },
    {
      "name": "CVE-2021-4028",
      "url": "https://www.cve.org/CVERecord?id=CVE-2021-4028"
    }
  ],
  "initial_release_date": "2022-09-02T00:00:00",
  "last_revision_date": "2022-09-02T00:00:00",
  "links": [],
  "reference": "CERTFR-2022-AVI-792",
  "revisions": [
    {
      "description": "Version initiale",
      "revision_date": "2022-09-02T00:00:00.000000"
    }
  ],
  "risks": [
    {
      "description": "D\u00e9ni de service \u00e0 distance"
    }
  ],
  "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits F5.\nElles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code\narbitraire, un d\u00e9ni de service \u00e0 distance et une \u00e9l\u00e9vation de\nprivil\u00e8ges.\n",
  "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits F5",
  "vendor_advisories": [
    {
      "published_at": null,
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K50839343 du 01 septembre 2022",
      "url": "https://support.f5.com/csp/article/K50839343"
    }
  ]
}

CERTFR-2022-AVI-063
Vulnerability from certfr_avis

De multiples vulnérabilités ont été découvertes dans F5 NGINX. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, un déni de service et un contournement de la politique de sécurité.

Solution

Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

None
Impacted products
Vendor Product Description
F5 NGINX NGINX App Protect versions 3.x antérieures à 3.7.0
F5 NGINX NGINX Controller API Management versions 3.x antérieures à 3.19.1

Show details on source website


{
  "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
  "affected_systems": [
    {
      "description": "NGINX App Protect versions 3.x ant\u00e9rieures \u00e0 3.7.0",
      "product": {
        "name": "NGINX",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "NGINX Controller API Management versions 3.x ant\u00e9rieures \u00e0 3.19.1",
      "product": {
        "name": "NGINX",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    }
  ],
  "affected_systems_content": null,
  "content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
  "cves": [
    {
      "name": "CVE-2022-23008",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-23008"
    }
  ],
  "initial_release_date": "2022-01-20T00:00:00",
  "last_revision_date": "2022-01-20T00:00:00",
  "links": [],
  "reference": "CERTFR-2022-AVI-063",
  "revisions": [
    {
      "description": "Version initiale",
      "revision_date": "2022-01-20T00:00:00.000000"
    }
  ],
  "risks": [
    {
      "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
    },
    {
      "description": "Ex\u00e9cution de code arbitraire"
    },
    {
      "description": "D\u00e9ni de service"
    },
    {
      "description": "Contournement de la politique de s\u00e9curit\u00e9"
    },
    {
      "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
    }
  ],
  "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans F5 NGINX. Certaines\nd\u0027entre elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de\ncode arbitraire, un d\u00e9ni de service et un contournement de la politique\nde s\u00e9curit\u00e9.\n",
  "title": "Multiples vuln\u00e9rabilit\u00e9s dans F5 NGINX",
  "vendor_advisories": [
    {
      "published_at": null,
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K57735782 du 19 janvier 2022",
      "url": "https://support.f5.com/csp/article/K57735782"
    },
    {
      "published_at": null,
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K30911244 du 19 janvier 2022",
      "url": "https://support.f5.com/csp/article/K30911244"
    },
    {
      "published_at": null,
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K41503304 du 19 janvier 2022",
      "url": "https://support.f5.com/csp/article/K41503304"
    }
  ]
}

CERTFR-2021-AVI-918
Vulnerability from certfr_avis

Une vulnérabilité a été découverte dans F5 NGINX. Elle permet à un attaquant de provoquer un déni de service à distance.

Solution

Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

None
Impacted products
Vendor Product Description
F5 NGINX NGINX ModSecurity WAF versions R25 antérieures à R25+1.0.2-3
F5 NGINX NGINX ModSecurity WAF versions R24 antérieures à R24+1.0.2-2
References

Show details on source website


{
  "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
  "affected_systems": [
    {
      "description": "NGINX ModSecurity WAF versions R25 ant\u00e9rieures \u00e0 R25+1.0.2-3",
      "product": {
        "name": "NGINX",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    },
    {
      "description": "NGINX ModSecurity WAF versions R24 ant\u00e9rieures \u00e0 R24+1.0.2-2",
      "product": {
        "name": "NGINX",
        "vendor": {
          "name": "F5",
          "scada": false
        }
      }
    }
  ],
  "affected_systems_content": null,
  "content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
  "cves": [
    {
      "name": "CVE-2021-42717",
      "url": "https://www.cve.org/CVERecord?id=CVE-2021-42717"
    }
  ],
  "initial_release_date": "2021-12-06T00:00:00",
  "last_revision_date": "2021-12-06T00:00:00",
  "links": [],
  "reference": "CERTFR-2021-AVI-918",
  "revisions": [
    {
      "description": "Version initiale",
      "revision_date": "2021-12-06T00:00:00.000000"
    }
  ],
  "risks": [
    {
      "description": "D\u00e9ni de service \u00e0 distance"
    }
  ],
  "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans F5 NGINX. Elle permet \u00e0 un\nattaquant de provoquer un d\u00e9ni de service \u00e0 distance.\n",
  "title": "Vuln\u00e9rabilit\u00e9 dans F5 NGINX",
  "vendor_advisories": [
    {
      "published_at": null,
      "title": "Bulletin de s\u00e9curit\u00e9 F5 K50839343 du 03 d\u00e9cembre 2021",
      "url": "https://support.f5.com/csp/article/K50839343"
    }
  ]
}

CVE-2022-41742 (GCVE-0-2022-41742)
Vulnerability from cvelistv5
Published
2022-10-19 21:20
Modified
2025-05-08 18:11
CWE
Summary
NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted audio or video file. The issue affects only NGINX products that are built with the module ngx_http_mp4_module, when the mp4 directive is used in the configuration file. Further, the attack is possible only if an attacker can trigger processing of a specially crafted audio or video file with the module ngx_http_mp4_module.
Impacted products
Vendor Product Version
F5 NGINX Version: Mainline   < 1.23.2
Version: Stable   < 1.22.1
Create a notification for this product.
   F5 NGINX Plus Version: R27   < R27-p1
Version: R1   < R26-p1
Create a notification for this product.
   F5 NGINX Open Source Subscription Version: R2   < R2 P1
Version: R1   < R1 P1
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-03T12:49:44.037Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://support.f5.com/csp/article/K28112382"
          },
          {
            "name": "FEDORA-2022-b0f5bc2175",
            "tags": [
              "vendor-advisory",
              "x_transferred"
            ],
            "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BPRVYA4FS34VWB4FEFYNAD7Z2LFCJVEI/"
          },
          {
            "name": "FEDORA-2022-97de53f202",
            "tags": [
              "vendor-advisory",
              "x_transferred"
            ],
            "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FD6M3PVVKO35WLAA7GLDBS6TEQ26SM64/"
          },
          {
            "name": "FEDORA-2022-12721789aa",
            "tags": [
              "vendor-advisory",
              "x_transferred"
            ],
            "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WBORRVG7VVXYOAIAD64ZHES2U2VIUKFQ/"
          },
          {
            "name": "DSA-5281",
            "tags": [
              "vendor-advisory",
              "x_transferred"
            ],
            "url": "https://www.debian.org/security/2022/dsa-5281"
          },
          {
            "name": "[debian-lts-announce] 20221122 [SECURITY] [DLA 3203-1] nginx security update",
            "tags": [
              "mailing-list",
              "x_transferred"
            ],
            "url": "https://lists.debian.org/debian-lts-announce/2022/11/msg00031.html"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://security.netapp.com/advisory/ntap-20230120-0005/"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2022-41742",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-05-08T18:11:21.947795Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-05-08T18:11:30.671Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "NGINX",
          "vendor": "F5",
          "versions": [
            {
              "lessThan": "1.23.2",
              "status": "affected",
              "version": "Mainline",
              "versionType": "custom"
            },
            {
              "lessThan": "1.22.1",
              "status": "affected",
              "version": "Stable",
              "versionType": "custom"
            }
          ]
        },
        {
          "product": "NGINX Plus",
          "vendor": "F5",
          "versions": [
            {
              "lessThan": "R27-p1",
              "status": "affected",
              "version": "R27",
              "versionType": "custom"
            },
            {
              "lessThan": "R26-p1",
              "status": "affected",
              "version": "R1",
              "versionType": "custom"
            }
          ]
        },
        {
          "product": "NGINX Open Source Subscription",
          "vendor": "F5",
          "versions": [
            {
              "lessThan": "R2 P1",
              "status": "affected",
              "version": "R2",
              "versionType": "custom"
            },
            {
              "lessThan": "R1 P1",
              "status": "affected",
              "version": "R1",
              "versionType": "custom"
            }
          ]
        }
      ],
      "datePublic": "2022-10-19T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted audio or video file. The issue affects only NGINX products that are built with the module ngx_http_mp4_module, when the mp4 directive is used in the configuration file. Further, the attack is possible only if an attacker can trigger processing of a specially crafted audio or video file with the module ngx_http_mp4_module."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
            "version": "3.1"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-787",
              "description": "CWE-787 Out-of-bounds Write",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2023-01-20T00:00:00.000Z",
        "orgId": "9dacffd4-cb11-413f-8451-fbbfd4ddc0ab",
        "shortName": "f5"
      },
      "references": [
        {
          "url": "https://support.f5.com/csp/article/K28112382"
        },
        {
          "name": "FEDORA-2022-b0f5bc2175",
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BPRVYA4FS34VWB4FEFYNAD7Z2LFCJVEI/"
        },
        {
          "name": "FEDORA-2022-97de53f202",
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FD6M3PVVKO35WLAA7GLDBS6TEQ26SM64/"
        },
        {
          "name": "FEDORA-2022-12721789aa",
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WBORRVG7VVXYOAIAD64ZHES2U2VIUKFQ/"
        },
        {
          "name": "DSA-5281",
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://www.debian.org/security/2022/dsa-5281"
        },
        {
          "name": "[debian-lts-announce] 20221122 [SECURITY] [DLA 3203-1] nginx security update",
          "tags": [
            "mailing-list"
          ],
          "url": "https://lists.debian.org/debian-lts-announce/2022/11/msg00031.html"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20230120-0005/"
        }
      ],
      "source": {
        "defect": [
          "NWA-1396"
        ],
        "discovery": "EXTERNAL"
      },
      "title": "NGINX ngx_http_mp4_module vulnerability CVE-2022-41742",
      "x_generator": {
        "engine": "Vulnogram 0.0.9"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "9dacffd4-cb11-413f-8451-fbbfd4ddc0ab",
    "assignerShortName": "f5",
    "cveId": "CVE-2022-41742",
    "datePublished": "2022-10-19T21:20:50.106Z",
    "dateReserved": "2022-09-28T00:00:00.000Z",
    "dateUpdated": "2025-05-08T18:11:30.671Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}

CVE-2022-41741 (GCVE-0-2022-41741)
Vulnerability from cvelistv5
Published
2022-10-19 21:20
Modified
2025-05-08 18:12
CWE
Summary
NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to corrupt NGINX worker memory, resulting in its termination or potential other impact using a specially crafted audio or video file. The issue affects only NGINX products that are built with the ngx_http_mp4_module, when the mp4 directive is used in the configuration file. Further, the attack is possible only if an attacker can trigger processing of a specially crafted audio or video file with the module ngx_http_mp4_module.
Impacted products
Vendor Product Version
F5 NGINX Version: Mainline   < 1.23.2
Version: Stable   < 1.22.1
Create a notification for this product.
   F5 NGINX Plus Version: R27   < R27-p1
Version: R1   < R26-p1
Create a notification for this product.
   F5 NGINX Open Source Subscription Version: R2   < R2 P1
Version: R1   < R1 P1
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-03T12:49:43.730Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://support.f5.com/csp/article/K81926432"
          },
          {
            "name": "FEDORA-2022-b0f5bc2175",
            "tags": [
              "vendor-advisory",
              "x_transferred"
            ],
            "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BPRVYA4FS34VWB4FEFYNAD7Z2LFCJVEI/"
          },
          {
            "name": "FEDORA-2022-97de53f202",
            "tags": [
              "vendor-advisory",
              "x_transferred"
            ],
            "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FD6M3PVVKO35WLAA7GLDBS6TEQ26SM64/"
          },
          {
            "name": "FEDORA-2022-12721789aa",
            "tags": [
              "vendor-advisory",
              "x_transferred"
            ],
            "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WBORRVG7VVXYOAIAD64ZHES2U2VIUKFQ/"
          },
          {
            "name": "DSA-5281",
            "tags": [
              "vendor-advisory",
              "x_transferred"
            ],
            "url": "https://www.debian.org/security/2022/dsa-5281"
          },
          {
            "name": "[debian-lts-announce] 20221122 [SECURITY] [DLA 3203-1] nginx security update",
            "tags": [
              "mailing-list",
              "x_transferred"
            ],
            "url": "https://lists.debian.org/debian-lts-announce/2022/11/msg00031.html"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://security.netapp.com/advisory/ntap-20230120-0005/"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2022-41741",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-05-08T18:12:04.179522Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-05-08T18:12:10.565Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "NGINX",
          "vendor": "F5",
          "versions": [
            {
              "lessThan": "1.23.2",
              "status": "affected",
              "version": "Mainline",
              "versionType": "custom"
            },
            {
              "lessThan": "1.22.1",
              "status": "affected",
              "version": "Stable",
              "versionType": "custom"
            }
          ]
        },
        {
          "product": "NGINX Plus",
          "vendor": "F5",
          "versions": [
            {
              "lessThan": "R27-p1",
              "status": "affected",
              "version": "R27",
              "versionType": "custom"
            },
            {
              "lessThan": "R26-p1",
              "status": "affected",
              "version": "R1",
              "versionType": "custom"
            }
          ]
        },
        {
          "product": "NGINX Open Source Subscription",
          "vendor": "F5",
          "versions": [
            {
              "lessThan": "R2 P1",
              "status": "affected",
              "version": "R2",
              "versionType": "custom"
            },
            {
              "lessThan": "R1 P1",
              "status": "affected",
              "version": "R1",
              "versionType": "custom"
            }
          ]
        }
      ],
      "datePublic": "2022-10-19T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to corrupt NGINX worker memory, resulting in its termination or potential other impact using a specially crafted audio or video file. The issue affects only NGINX products that are built with the ngx_http_mp4_module, when the mp4 directive is used in the configuration file. Further, the attack is possible only if an attacker can trigger processing of a specially crafted audio or video file with the module ngx_http_mp4_module."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "HIGH",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-787",
              "description": "CWE-787 Out-of-bounds Write",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2023-01-20T00:00:00.000Z",
        "orgId": "9dacffd4-cb11-413f-8451-fbbfd4ddc0ab",
        "shortName": "f5"
      },
      "references": [
        {
          "url": "https://support.f5.com/csp/article/K81926432"
        },
        {
          "name": "FEDORA-2022-b0f5bc2175",
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BPRVYA4FS34VWB4FEFYNAD7Z2LFCJVEI/"
        },
        {
          "name": "FEDORA-2022-97de53f202",
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FD6M3PVVKO35WLAA7GLDBS6TEQ26SM64/"
        },
        {
          "name": "FEDORA-2022-12721789aa",
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WBORRVG7VVXYOAIAD64ZHES2U2VIUKFQ/"
        },
        {
          "name": "DSA-5281",
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://www.debian.org/security/2022/dsa-5281"
        },
        {
          "name": "[debian-lts-announce] 20221122 [SECURITY] [DLA 3203-1] nginx security update",
          "tags": [
            "mailing-list"
          ],
          "url": "https://lists.debian.org/debian-lts-announce/2022/11/msg00031.html"
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20230120-0005/"
        }
      ],
      "source": {
        "defect": [
          "NWA-1396"
        ],
        "discovery": "EXTERNAL"
      },
      "title": "NGINX ngx_http_mp4_module vulnerability CVE-2022-41741",
      "x_generator": {
        "engine": "Vulnogram 0.0.9"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "9dacffd4-cb11-413f-8451-fbbfd4ddc0ab",
    "assignerShortName": "f5",
    "cveId": "CVE-2022-41741",
    "datePublished": "2022-10-19T21:20:24.882Z",
    "dateReserved": "2022-09-28T00:00:00.000Z",
    "dateUpdated": "2025-05-08T18:12:10.565Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}