CVE-2024-24966: F5OS vulnerability
When LDAP remote authentication is configured on F5OS, a remote user without an assigned role will be incorrectly authorized.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
F5 F5OSto a version that resolves this vulnerability.Fixed in 1.3.0 - Upgrade
Upgrade
F5 F5OSto a version that resolves this vulnerability.Fixed in 1.6.0
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24966?
The severity of CVE-2024-24966 has not been explicitly rated, but it affects user authorization and can lead to unauthorized access.
How do I fix CVE-2024-24966?
To fix CVE-2024-24966, update your F5OS software to a version that is not affected by this vulnerability.
Which software versions are affected by CVE-2024-24966?
CVE-2024-24966 affects F5OS-A version 1.2.0 and F5OS-C versions between 1.3.0 and 1.5.1.
Can CVE-2024-24966 be exploited remotely?
Yes, CVE-2024-24966 can be exploited remotely due to the improper authorization of users during LDAP authentication.
What happens if a remote user without an assigned role accesses F5OS in CVE-2024-24966?
A remote user without an assigned role may gain unauthorized access due to incorrect authorization mechanisms in place.