New BIG-IP Next Central Manager bugs allow device takeover
ID: 0fc96aa1-0059-555d-b27b-5da9d710d6a0
STIX ID: report--0fc96aa1-0059-555d-b27b-5da9d710d6a0
Feed Name: Bleeping Computer
Threat Score
F5 patched two high-severity vulnerabilities in BIG-IP Next Central Manager (CVE-2024-26026 and CVE-2024-21793) that permit unauthenticated remote SQL/OData injection leading to full administrative takeover and creation of hidden rogue accounts on managed BIG-IP Next assets; Eclypsium published a PoC and recommends patching or restricting access, and F5 advises applying updates or limiting management UI access as a temporary mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
