CVE-2024-41719: BIG-IP Next Central Manager vulnerability
When generating QKView of BIG-IP Next instance from the BIG-IP Next Central Manager (CM), F5 iHealth credentials will be logged in the BIG-IP Central Manager logs. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Other sources
When you generate a QKView file of a BIG-IP Next instance from the BIG-IP Next Central Manager, F5 iHealth credentials are logged in the BIG-IP Central Manager log file.
— F5
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41719?
CVE-2024-41719 has been classified as a medium severity vulnerability due to the potential exposure of sensitive information in logs.
How do I fix CVE-2024-41719?
To fix CVE-2024-41719, it is recommended to upgrade the F5 BIG-IP Next Central Manager to a version that is not affected by this vulnerability.
What versions of F5 BIG-IP Next Central Manager are affected by CVE-2024-41719?
Versions 20.1.0 to 20.2.0 of F5 BIG-IP Next Central Manager are affected by CVE-2024-41719.
What information is exposed in CVE-2024-41719?
CVE-2024-41719 exposes F5 iHealth credentials in the BIG-IP Central Manager logs.
Is there a workaround for CVE-2024-41719?
Currently, there are no documented workarounds for CVE-2024-41719, and upgrading to a patched version is the suggested mitigation.