First published: Wed Aug 14 2024(Updated: )
BIG-IP Next Central Manager may allow an attacker to lock out an account that has never been logged in.
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 BIG-IP Next Central Manager | >=20.1.0<=20.2.0 | 20.2.1 |
F5 BIG-IP Next Central Manager | >=20.1.0<20.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-37028 is considered a significant vulnerability as it allows account lockout for users that have never logged in.
To fix CVE-2024-37028, upgrade the F5 BIG-IP Next Central Manager to a version that is not affected, specifically above 20.2.1.
F5 BIG-IP Next Central Manager versions from 20.1.0 to 20.2.0 are affected by CVE-2024-37028.
Any user of the F5 BIG-IP Next Central Manager within the affected versions may be impacted by CVE-2024-37028.
Yes, CVE-2024-37028 can potentially be exploited remotely by an attacker with access to the management interface.