First published: Wed Feb 14 2024(Updated: )
When LDAP remote authentication is configured on F5OS, a remote user without an assigned role will be incorrectly authorized. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 F5OS | =1.2.0 | 1.3.0 |
F5 F5OS | >=1.3.0<=1.5.1 | 1.6.0 |
F5 F5OS | =1.2.0 | |
F5 F5OS | >=1.3.0<1.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-24966 has not been explicitly rated, but it affects user authorization and can lead to unauthorized access.
To fix CVE-2024-24966, update your F5OS software to a version that is not affected by this vulnerability.
CVE-2024-24966 affects F5OS-A version 1.2.0 and F5OS-C versions between 1.3.0 and 1.5.1.
Yes, CVE-2024-24966 can be exploited remotely due to the improper authorization of users during LDAP authentication.
A remote user without an assigned role may gain unauthorized access due to incorrect authorization mechanisms in place.