logo

2 (or 5) Bugs in F5 Asset Manager Allow Full Takeover, Hidden Accounts

ID: 3fcef6d2-ff77-53e2-8906-94faba1aad6e

STIX ID: report--3fcef6d2-ff77-53e2-8906-94faba1aad6e

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-05-09

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Eclypsium disclosed multiple vulnerabilities in F5 BIG-IP Next Central Manager: two high-severity bugs (CVE-2024-21793 OData injection and CVE-2024-26026 SQL injection) that can expose admin password hashes and enable privilege escalation (patched in version 20.2.0), plus three additional unpatched issues—an SSRF allowing API calls that can create hidden accounts on managed devices, weak bcrypt-hashed admin passwords susceptible to brute force, and the ability for authenticated admins to reset passwords without knowing the prior password—any of which could permit persistent, stealthy access to managed edge devices if abused.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.