First published: Wed Aug 14 2024(Updated: )
BIG-IP Next Central Manager may allow an attacker to lock out an account that has never been logged in.
Affected Software | Affected Version | How to fix |
---|---|---|
F5 BIG-IP Next Central Manager | >=20.1.0<=20.2.0 | 20.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of F5-K000139938 is classified as a medium risk due to the potential for account lockout without prior login.
To fix F5-K000139938, upgrade your BIG-IP Next Central Manager to versions 20.2.1 or higher.
F5-K000139938 affects F5 BIG-IP Next Central Manager versions from 20.1.0 to 20.2.0.
F5-K000139938 does not directly lead to unauthorized access but allows an attacker to lock out valid accounts.
There is no specific workaround for F5-K000139938, the recommended solution is to apply the software update.