Skip to main content

F5 Releases Quarterly Security Notification (May 2024) Affecting BIG-IP Products

Proof-of-concept exploit code released for 2 high severity vulnerabilities affecting BIG-IP Next Central Manager

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Proof-of-concept exploit code released for 2 high severity vulnerabilities affecting BIG-IP Next Central Manager


The following platforms are also known to be affected:

  • NGINX App Protect WAF

Threat details

Introduction

F5 has released an overview of vulnerabilities for some of their networking products, including BIG-IP and BIG-IP Next Central Manager. The security advisory addresses seven vulnerabilities rated as high impact, six rated as medium impact and three security exposures.

An attacker could exploit some of these vulnerabilities to execute malicious SQL statements, conduct a man-in-the-middle attack, carry out cross-site scripting (XSS) attacks, or create a denial-of-service (DoS) condition.

Proof-of-concept exploit code for vulnerabilities in BIG-IP Next Central Manager

A cyber security firm has released proof-of-concept exploit code for two vulnerabilities that affect BIG-IP Next Central Manager. The management console of the Central Manager can be remotely exploited by any attacker able to access the administrative UI (user interface) via the vulnerabilities CVE 2024-21793 or CVE 2024-26026, giving the attacker full administrative control of the manager itself.

Attackers can then take advantage of the other vulnerabilities to create new accounts on any BIG-IP Next asset managed by the Central Manager. These new malicious accounts would not be visible from the Central Manager itself. 

Exploitation of these vulnerabilities is considered more likely.


Remediation advice

Affected organisations are strongly encouraged to review K000139404: Quarterly Security Notification (May 2024) and apply any relevant updates or mitigation.


Definitive source of threat updates


CVE Vulnerabilities

Last edited: 9 May 2024 1:33 pm