F5-K000139938: Medium severity f5 big-ip next central manager vulnerability
Published Aug 14, 2024
·Updated
BIG-IP Next Central Manager may allow an attacker to lock out an account that has never been logged in.
Affected Software
1 affected componentFixes available
F5 BIG-IP Next Central Manager>=20.1.0<=20.2.0
20.2.1
Event History
Aug 14, 2024
Advisory Published
via F5·01:21 PM
Frequently Asked Questions
1
What is the severity of F5-K000139938?
The severity of F5-K000139938 is classified as a medium risk due to the potential for account lockout without prior login.
2
How do I fix F5-K000139938?
To fix F5-K000139938, upgrade your BIG-IP Next Central Manager to versions 20.2.1 or higher.
3
What versions are affected by F5-K000139938?
F5-K000139938 affects F5 BIG-IP Next Central Manager versions from 20.1.0 to 20.2.0.
4
Can F5-K000139938 lead to unauthorized access?
F5-K000139938 does not directly lead to unauthorized access but allows an attacker to lock out valid accounts.
5
Is there a workaround for F5-K000139938?
There is no specific workaround for F5-K000139938, the recommended solution is to apply the software update.