CVE-2024-33612: BIG-IP Next Central Manager vulnerability
An improper certificate validation vulnerability exists in BIG-IP Next Central Manager and may allow an attacker to impersonate an Instance Provider system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Other sources
An improper certificate validation vulnerability exists in BIG-IP Next Central Manager and may allow an attacker to impersonate an Instance Provider system. A successful exploit of this vulnerability can allow the attacker to cross a security boundary.
— F5
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-33612?
CVE-2024-33612 is a high severity vulnerability due to improper certificate validation in BIG-IP Next Central Manager.
How does CVE-2024-33612 affect my systems?
CVE-2024-33612 can allow an attacker to impersonate an Instance Provider, potentially enabling them to cross security boundaries.
How do I fix CVE-2024-33612?
To fix CVE-2024-33612, update the BIG-IP Next Central Manager to a version that addresses this vulnerability.
What versions of BIG-IP Next Central Manager are affected by CVE-2024-33612?
CVE-2024-33612 affects versions of BIG-IP Next Central Manager from 20.0.1 to 20.2.0.
Is there a workaround for CVE-2024-33612?
Currently, the best mitigation for CVE-2024-33612 is to apply the latest patches provided by F5.