CVE-2025-23413: BIG-IP Next Central Manager vulnerability
Published Feb 5, 2025
·Updated
When users log in through the webUI or API using local authentication, BIG-IP Next Central Manager may log sensitive information in the pgaudit log files.
Affected Software
2 affected componentsFixes available
F5 BIG-IP Next Central Manager>=20.2.0<=20.2.1
20.3.0
F5 BIG-IP Next Central Manager>=20.2.0<20.3.0
Event History
Feb 5, 2025
Advisory Published
via F5·01:58 PM
CVE Published
via MITRE·05:31 PM
Data Sourced
via MITRE·05:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-23413?
CVE-2025-23413 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2025-23413?
Fixing CVE-2025-23413 involves updating to versions of F5 BIG-IP Next Central Manager beyond 20.3.0.
3
What type of information is logged in CVE-2025-23413?
CVE-2025-23413 logs sensitive user authentication details in the pgaudit log files.
4
Which versions of BIG-IP Next Central Manager are affected by CVE-2025-23413?
CVE-2025-23413 affects F5 BIG-IP Next Central Manager versions between 20.2.0 and 20.2.1.
5
Does CVE-2025-23413 affect API logins as well?
Yes, CVE-2025-23413 impacts both webUI and API logins using local authentication.