Critical Vulnerabilities in F5 Central Manager Enable Unauthorized Access and Device Takeover

Published:

spot_img

F5 Central Manager Vulnerabilities: Critical Flaws Discovered

A new report by security firm Eclypsium has revealed two critical vulnerabilities in F5 Next Central Manager that could potentially be exploited by threat actors to take control of devices and create hidden rogue administrator accounts. The flaws, labelled as CVE-2024-21793 and CVE-2024-26026, have a CVSS score of 7.5 each and impact Next Central Manager versions from 20.0.1 to 20.1.0. The vulnerabilities have been patched in version 20.2.0.

If exploited, these vulnerabilities could grant attackers full administrative control of the device, allowing them to create accounts on any F5 assets managed by the Central Manager. What is particularly concerning is that the created accounts would remain hidden from the Central Manager due to a server-side request forgery (SSRF) vulnerability, enabling attackers to maintain persistence even after the system has been patched.

In addition, Eclypsium also identified two more weaknesses that could facilitate brute-force attacks against admin passwords and enable password resets without knowledge of the previous password. This could potentially allow attackers to block legitimate access to the device from any account.

While there are currently no reports of active exploitation in the wild, users are strongly advised to update their instances to the latest version to safeguard against potential threats. As cyberattacks targeting networking and application infrastructure continue to rise, it is crucial for organizations to stay vigilant and prioritize security measures to prevent unauthorized access and maintain the integrity of their systems.

spot_img

Related articles

Recent articles

Webinar: Uncovering Suspicious APK Files in Wedding Card and Loan App Scams

The surge of malicious APK files in cyber fraud schemes, such as fake wedding invitations and instant loan applications, has become a growing concern....

Skylon Partners with COBNB to Launch COBNB+ Featuring L’Occitane en Provence Hotel Amenities

Skylon Partners with COBNB for a Luxurious Hospitality Experience in Kuala Lumpur Introduction to the New Partnership In an exciting development for the hospitality scene in...

Understanding CISA KEV: Key Insights and Tools for Security Teams

Understanding the CISA Known Exploited Vulnerability (KEV) Catalog The Cybersecurity and Infrastructure Security Agency (CISA) maintains the Known Exploited Vulnerability (KEV) catalog, a resource designed...

Dark Web Leak Sparks WFH Job Scams; Prayagraj Police Freeze ₹2 Crore in Fraudulent Funds

Rising Cybercrime in Prayagraj: A New Target Shifting Tactics of Cybercriminals In Prayagraj, the landscape of cybercrime is evolving. Previously, scammers predominantly targeted victims through enticing...