2 (or 5) Bugs in F5 Asset Manager Allow Full Takeover, Hidden Accounts
ID: 3fcef6d2-ff77-53e2-8906-94faba1aad6e
STIX ID: report--3fcef6d2-ff77-53e2-8906-94faba1aad6e
Feed Name: Dark Reading
Eclypsium disclosed multiple vulnerabilities in F5 BIG-IP Next Central Manager: two high-severity bugs (CVE-2024-21793 OData injection and CVE-2024-26026 SQL injection) that can expose admin password hashes and enable privilege escalation (patched in version 20.2.0), plus three additional unpatched issues—an SSRF allowing API calls that can create hidden accounts on managed devices, weak bcrypt-hashed admin passwords susceptible to brute force, and the ability for authenticated admins to reset passwords without knowing the prior password—any of which could permit persistent, stealthy access to managed edge devices if abused.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
