CVE-2024-41719

Severity
5.1MEDIUM
EPSS
0.2%
top 60.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 14

Description

When generating QKView of BIG-IP Next instance from the BIG-IP Next Central Manager (CM), F5 iHealth credentials will be logged in the BIG-IP Central Manager logs. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Packages2 packages

CVEListV5f5/big-ip_next_central_manager20.1.020.2.1
NVDf5/big-ip_next_central_manager20.1.020.2.1

🔴Vulnerability Details

2
GHSA
GHSA-wrw4-qghx-vfxm: When generating QKView of BIG-IP Next instance from the BIG-IP Next Central Manager (CM), F5 iHealth credentials will be logged in the BIG-IP Central2024-08-14
CVEList
BIG-IP Next Central Manager vulnerability2024-08-14

📋Vendor Advisories

1
F5
CVE-2024-41719: When generating QKView of BIG-IP Next instance from the BIG-IP Next Central Manager (CM), F5 iHealth credentials wil...2024-08-14
CVE-2024-41719 (MEDIUM CVSS 5.1) | When generating QKView of BIG-IP Ne | cvebase.io