Skip to main content

Vendor/product archive

f5 / big-ip_next_central_manager CVEs

Beta · best-effort

12 CVEs tagged to f5 / big-ip_next_central_manager0 Critical, 7 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2025-24319

Published Feb 5, 2025

When BIG-IP Next Central Manager is running, undisclosed requests to the BIG-IP Next Central Manager API can cause the BIG-IP Next Central Manager Node's Kubernetes service to ter…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-23413

Published Feb 5, 2025

When users log in through the webUI or API using local authentication, BIG-IP Next Central Manager may log sensitive information in the pgaudit log files. Note: Software versio…

CVSS 6.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-41719

Published Aug 14, 2024

When generating QKView of BIG-IP Next instance from the BIG-IP Next Central Manager (CM), F5 iHealth credentials will be logged in the BIG-IP Central Manager logs.  Note: Softwar…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-39809

Published Aug 14, 2024

The Central Manager user session refresh token does not expire when a user logs out.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVSS 8.9 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-37028

Published Aug 14, 2024

BIG-IP Next Central Manager may allow an attacker to lock out an account that has never been logged in.  Note: Software versions which have reached End of Technical Support (EoTS)…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-33612

Published May 8, 2024

An improper certificate validation vulnerability exists in BIG-IP Next Central Manager and may allow an attacker to impersonate an Instance Provider system.  Note: Software versio…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-32049

Published May 8, 2024

BIG-IP Next Central Manager (CM) may allow an unauthenticated, remote attacker to obtain the BIG-IP Next LTM/WAF instance credentials.  Note: Software versions which have reached…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-26026

Published May 8, 2024

An SQL injection vulnerability exists in the BIG-IP Next Central Manager API (URI).  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVSS 7.5 · High
evidence mentions
6
Buzz score
34.0
Vendor/product tagsBeta · best-effort

CVE-2024-21793

Published May 8, 2024

An OData injection vulnerability exists in the BIG-IP Next Central Manager API (URI).  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS 7.5 · High
evidence mentions
6
Buzz score
34.0
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1