CVE-2024-32049: BIG-IP Next Central Manager vulnerability
BIG-IP Next Central Manager (CM) may allow an unauthenticated, remote attacker to obtain the BIG-IP Next LTM/WAF instance credentials.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Other sources
BIG-IP Next Central Manager may allow an unauthenticated, remote attacker to obtain BIG-IP Next LTM/WAF instance credentials.
— F5
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-32049?
CVE-2024-32049 is considered a critical vulnerability as it allows unauthenticated remote attackers to obtain sensitive credentials.
How do I fix CVE-2024-32049?
To fix CVE-2024-32049, upgrade to a supported version of F5 BIG-IP Next Central Manager that is not affected by this vulnerability.
Which versions of F5 BIG-IP Next Central Manager are affected by CVE-2024-32049?
CVE-2024-32049 affects versions of F5 BIG-IP Next Central Manager from 20.0.1 to 20.0.2.
Can software that has reached End of Technical Support (EoTS) be vulnerable to CVE-2024-32049?
Software versions that have reached End of Technical Support (EoTS) are not evaluated for CVE-2024-32049.
What should I do if I cannot upgrade my F5 BIG-IP Next Central Manager to fix CVE-2024-32049?
If you cannot upgrade, consider implementing network controls such as firewalls or access controls to limit exposure until an upgrade can be performed.