my.f5.comVendor advisory
https://my.f5.com/manage/s/article/K000138732 CVE-2024-21793
HIGH
BIG-IP Central Manager OData Injection Vulnerability
Record summary
CVE-2024-21793 has a selected CVSS score of 7.5 (high); EIP currently links 1 repository PoC.
Description
An OData injection vulnerability exists in the BIG-IP Next Central Manager API (URI). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Description source: CVE List
Exploitation context
Available material
- Repository PoCs
- 1
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 8, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
BIG-IP Next Central ManagerBrowse F5 / BIG-IP Next Central ManagerDefault status: unknown | CVE List | 20.0.1 to < 20.2.0 | affected |
Proofs of concept
1Repository PoCs
GitHubFeatherStark/CVE-2024-21793Repository PoCby FeatherStarkStars: 0Not analyzed2 files
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-21793