F5 Releases Quarterly Security Notification (May 2024) Affecting BIG-IP Products
Proof-of-concept exploit code released for 2 high severity vulnerabilities affecting BIG-IP Next Central Manager
Summary
Proof-of-concept exploit code released for 2 high severity vulnerabilities affecting BIG-IP Next Central Manager
Affected platforms
The following platforms are known to be affected:
The following platforms are also known to be affected:
- NGINX App Protect WAF
Threat details
Introduction
F5 has released an overview of vulnerabilities for some of their networking products, including BIG-IP and BIG-IP Next Central Manager. The security advisory addresses seven vulnerabilities rated as high impact, six rated as medium impact and three security exposures.
An attacker could exploit some of these vulnerabilities to execute malicious SQL statements, conduct a man-in-the-middle attack, carry out cross-site scripting (XSS) attacks, or create a denial-of-service (DoS) condition.
Proof-of-concept exploit code for vulnerabilities in BIG-IP Next Central Manager
A cyber security firm has released proof-of-concept exploit code for two vulnerabilities that affect BIG-IP Next Central Manager. The management console of the Central Manager can be remotely exploited by any attacker able to access the administrative UI (user interface) via the vulnerabilities CVE 2024-21793 or CVE 2024-26026, giving the attacker full administrative control of the manager itself.
Attackers can then take advantage of the other vulnerabilities to create new accounts on any BIG-IP Next asset managed by the Central Manager. These new malicious accounts would not be visible from the Central Manager itself.
Exploitation of these vulnerabilities is considered more likely.
Remediation advice
Affected organisations are strongly encouraged to review K000139404: Quarterly Security Notification (May 2024) and apply any relevant updates or mitigation.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 9 May 2024 1:33 pm