Critical F5 Central Manager Vulnerabilities Allow Enable Full Device Takeover
ID: 2575f6cb-88df-5d00-89f8-144529613956
STIX ID: report--2575f6cb-88df-5d00-89f8-144529613956
Feed Name: The Hacker News
Two remotely exploitable SQL/OData injection vulnerabilities (CVE-2024-21793 and CVE-2024-26026; CVSS 7.5) in F5 BIG‑IP Next Central Manager (affecting 20.0.1–20.1.0) can allow unauthenticated attackers to execute SQL, gain full administrative control, and — via an SSRF invoking an undocumented API — create hidden administrator accounts that persist across managed assets; other issues enable brute‑force attacks and admin password resets. These flaws are resolved in version 20.2.0; no active exploitation has been observed, and users are advised to update immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
