CVE-2024-21793
published 2024-05-08CVE-2024-21793: An OData injection vulnerability exists in the BIG-IP Next Central Manager API (URI). Note: Software versions which have reached End of Technical Support…
PriorityP352high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
7.09%
93.5th percentile
An OData injection vulnerability exists in the BIG-IP Next Central Manager API (URI). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip_next_central_manager | — | — |
| f5 | big-ip_next_central_manager | >= 20.0.1 < 20.2.0 | 20.2.0 |
Detection & IOCsextracted from sources · hover to see the quote
snort
alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS F5 BIG-IP Next Central Manager OData Injection (CVE-2024-21793)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/api/login"; fast_pattern; startswith; http.content_type; content:"application/json"; http.request_body; content:"|22|username|22 3a|"; pcre:"/^[^\x27\x28\x29]*(?:\x27|\x28|\x29)+.*\x20+(?:(?:and|or|not|ge|le|ne|eq|lt|gt|has|in)\x20+|(?:(?:start|end)swith|length|indexof|substring|to(?:upper|lower)|trim|concat|round|floor|ceiling)\x28)/Ri"; content:"|22|provider_"; pcre:"/^(type|name)\x22\x3a\x20?\x22LDAP\x22/Ri"; reference:url,eclypsium.com/blog/big-vulnerabilities-in-next-gen-big-ip/; reference:cve,2024-21793; classtype:web-application-attack; sid:2056181; rev:1; metadata:affected_product F5, attack_target Server, tls_state plaintext, created_at 2024_09_25, cve CVE_2024_21793, deployment Perimeter, deployment Internal, performance_impact Low, confidence High, signature_severity Major, tag Exploit, updated_at 2024_09_25, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application; target:dest_ip;)
bytes↗
|22|username|22 3a|
bytes↗
|22|provider_
- →The OData injection is triggered via a POST request to the /api/login URI of the BIG-IP Next Central Manager API, with Content-Type: application/json and a JSON body containing a username field with OData operator injection (e.g., and/or/eq/lt/gt/has/in or OData functions like startswith, endswith, substring, etc.) combined with a provider_type or provider_name field set to "LDAP".
- →Post-exploitation: rogue accounts created on managed BIG-IP Next assets after compromise are NOT visible from the Central Manager UI — hunt for accounts on managed assets that have no corresponding record in Central Manager. ↗
- →Shodan exposure: over 10,000 F5 BIG-IP devices with management ports exposed online; prioritize hunting/patching internet-facing Central Manager instances. ↗
- →A public proof-of-concept exploit exists (published by Eclypsium); treat unpatched internet-facing instances as actively exploitable. ↗
- →MITRE mapping for this exploit: TA0001 (Initial Access) / T1190 (Exploit Public-Facing Application).
- ·Only BIG-IP Next Central Manager versions 20.0.1 through 20.2.0 are affected; EoTS (End of Technical Support) versions are not evaluated. ↗
- ·The Snort/ET rule targets plaintext (non-TLS) traffic only; encrypted management traffic will not be detected by this signature.
- ·F5 recommends that administrators who cannot immediately patch should restrict Next Central Manager access to trusted users over a secure network. ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w9q2-p57h-r357: An OData injection vulnerability exists in the BIG-IP Next Central Manager API (URI)
ghsa_unreviewed·2024-05-08
CVE-2024-21793 [HIGH] CWE-200 GHSA-w9q2-p57h-r357: An OData injection vulnerability exists in the BIG-IP Next Central Manager API (URI)
An OData injection vulnerability exists in the BIG-IP Next Central Manager API (URI). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
F5
CVE-2024-21793: An OData injection vulnerability exists in the BIG-IP Next Central Manager API (URI)
vendor_f5·2024-05-08·CVSS 7.5
CVE-2024-21793 [HIGH] CWE-89 CVE-2024-21793: An OData injection vulnerability exists in the BIG-IP Next Central Manager API (URI)
CVE-2024-21793: An OData injection vulnerability exists in the BIG-IP Next Central Manager API (URI)
An OData injection vulnerability exists in the BIG-IP Next Central Manager API (URI). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Products: BIG-IP Next Central Manager
Affected Versions: 20.0.1 - 20.2.0
F5 Advisory Articles: K000138732
F5 References: https://my.f5.com/manage/s/article/K000138732
Suricata
ET WEB_SPECIFIC_APPS F5 BIG-IP Next Central Manager OData Injection (CVE-2024-21793)
suricata·2024-09-25·CVSS 7.5
CVE-2024-21793 [HIGH] ET WEB_SPECIFIC_APPS F5 BIG-IP Next Central Manager OData Injection (CVE-2024-21793)
ET WEB_SPECIFIC_APPS F5 BIG-IP Next Central Manager OData Injection (CVE-2024-21793)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS F5 BIG-IP Next Central Manager OData Injection (CVE-2024-21793)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/api/login"; fast_pattern; startswith; http.content_type; content:"application/json"; http.request_body; content:"|22|username|22 3a|"; pcre:"/^[^\x27\x28\x29]*(?:\x27|\x28|\x29)+.*\x20+(?:(?:and|or|not|ge|le|ne|eq|lt|gt|has|in)\x20+|(?:(?:start|end)swith|length|indexof|substring|to(?:upper|lower)|trim|concat|round|floor|ceiling)\x28)/Ri"; content:"|22|provider_"; pcre:"/^(type|name)\x22\x3a\x20?\x22LDAP\x22/Ri"; reference:url,eclypsium.com/blog/big-vulnerabilities-in-next-gen-big-ip/; reference:cv
No public exploits indexed.
Checkpoint
13th May – Threat Intelligence Report
blogs_checkpoint·2024-05-13
CVE-2024-4671 13th May – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 13th May – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 13th May, please download our Threat_Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Shared Services Connected Ltd, a payroll contractor for the UK Ministry of Defense has been breached, presumably by China. Around 270k records that include names and bank details of both current and past armed forces members were exposed.
US major healthcare operator Ascension, which operates 140 hospitals in 19 states, has disc
Tenable
CVE-2024-21793, CVE-2024-26026: Proof of Concept Available for F5 BIG-IP Next Central Manager Vulnerabilities
blogs_tenable·2024-05-09·CVSS 7.5
[HIGH] CVE-2024-21793, CVE-2024-26026: Proof of Concept Available for F5 BIG-IP Next Central Manager Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bleepingcomputer
New BIG-IP Next Central Manager bugs allow device takeover
blogs_bleepingcomputer·2024-05-08·CVSS 7.5
CVE-2024-26026 [HIGH] New BIG-IP Next Central Manager bugs allow device takeover
## New BIG-IP Next Central Manager bugs allow device takeover
## Sergiu Gatlan
F5 has fixed two high-severity BIG-IP Next Central Manager vulnerabilities, which can be exploited to gain admin control and create hidden rogue accounts on any managed assets.
Next Central Manager allows administrators to control on-premises or cloud BIG-IP Next instances and services via a unified management user interface.
The flaws are an SQL injection vulnerability ( CVE-2024-26026 ) and an OData injection vulnerability ( CVE-2024-21793 ) found in the BIG-IP Next Central Manager API that would allow unauthenticated attackers to execute malicious SQL statements on unpatched devices remotely.
SQL injection attacks involve injecting malicious SQL queries into input fields or parameters in database queries
Greynoiseio
NoiseLetter May 2024
blogs_greynoiseio
NoiseLetter May 2024
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
2024-05-08
Published