F5 Vulnerabilities and Affected Products
Vulnerabilities associated with BIG-IP Next Central Manager.
Products
Clear product- BIG-IP257 vulnerabilities
- NGINX Plus31 vulnerabilities
- NGINX Open Source29 vulnerabilities
- BIG-IP Next CNF26 vulnerabilities
- BIG-IP Next SPK23 vulnerabilities
- BIG-IQ19 vulnerabilities
- BIG-IP Next for Kubernetes13 vulnerabilities
- BIG-IP APM12 vulnerabilities
- F5OS - Appliance12 vulnerabilities
- BIG-IP Edge Client11 vulnerabilities
- F5OS - Chassis10 vulnerabilities
- BIG-IP Next Central Manager9 vulnerabilities
- BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, FPS, GTM, Link Controller, PEM, WebAccelerator)8 vulnerabilities
- BIG-IQ Centralized Management7 vulnerabilities
- big-ip_next_central_manager6 vulnerabilities
- nginx6 vulnerabilities
- NGINX Ingress Controller5 vulnerabilities
- NGINX Instance Manager5 vulnerabilities
- nginx_plus5 vulnerabilities
- BIG-IP Guided Configuration (GC)4 vulnerabilities
- BIG-IP Next4 vulnerabilities
- F5OS-A4 vulnerabilities
- BIG-IP Advanced WAF & ASM3 vulnerabilities
- BIG-IP AFM3 vulnerabilities
- BIG-IP APM Clients3 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-23413MEDIUM | BIG-IP Next Central Manager vulnerabilityWhen users log in through the webUI or API using local authentication, BIG-IP Next Central Manager may log sensitive information in the pgaudit log files. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. CWE-532Feb 5, 2025 | CVSS6.7v4.0 | EPSS0.159% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-24319HIGH | BIG-IP Next Central Manager vulnerabilityWhen BIG-IP Next Central Manager is running, undisclosed requests to the BIG-IP Next Central Manager API can cause the BIG-IP Next Central Manager Node's Kubernetes service to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. CWE-20Feb 5, 2025 | CVSS7.1v4.0 | EPSS0.382% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-37028MEDIUM | BIG-IP Next Central Manager vulnerabilityBIG-IP Next Central Manager may allow an attacker to lock out an account that has never been logged in. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | CVSS6.3v4.0 | EPSS0.448% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-39809HIGH | BIG-IP Next Central Manager vulnerabilityThe Central Manager user session refresh token does not expire when a user logs out. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated CWE-613Aug 14, 2024 | CVSS8.9v4.0 | EPSS0.438% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-41719MEDIUM | BIG-IP Next Central Manager vulnerabilityWhen generating QKView of BIG-IP Next instance from the BIG-IP Next Central Manager (CM), F5 iHealth credentials will be logged in the BIG-IP Central Manager logs. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. CWE-532Aug 14, 2024 | CVSS5.1v4.0 | EPSS0.154% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-26026HIGH | BIG-IP Central Manager SQL InjectionAn SQL injection vulnerability exists in the BIG-IP Next Central Manager API (URI). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | CVSS7.5v3.1 | EPSS7.16% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-21793HIGH | BIG-IP Central Manager OData Injection VulnerabilityAn OData injection vulnerability exists in the BIG-IP Next Central Manager API (URI). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | CVSS7.5v3.1 | EPSS7.09% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33612MEDIUM | BIG-IP Next Central Manager vulnerabilityAn improper certificate validation vulnerability exists in BIG-IP Next Central Manager and may allow an attacker to impersonate an Instance Provider system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. CWE-295May 8, 2024 | CVSS6.8v3.1 | EPSS0.233% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-32049HIGH | BIG-IP Next Central Manager vulnerabilityBIG-IP Next Central Manager (CM) may allow an unauthenticated, remote attacker to obtain the BIG-IP Next LTM/WAF instance credentials. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. CWE-300May 8, 2024 | CVSS7.4v3.1 | EPSS0.548% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |