Record summary

CVE-2024-21793 has a selected CVSS score of 7.5 (high); EIP currently links 1 repository PoC.

Description

An OData injection vulnerability exists in the BIG-IP Next Central Manager API (URI).  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated May 8, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

BIG-IP Next Central Manager

Browse F5 / BIG-IP Next Central Manager

Default status: unknown

CVE List20.0.1 to < 20.2.0affected

Proofs of concept

1

Repository PoCs

GitHubFeatherStark/CVE-2024-21793Repository PoCby FeatherStarkStars: 0Not analyzed2 files

1.4 KiB

GitHub

PoC details

References

2