CVE-2024-41723
published 2024-08-14CVE-2024-41723: Undisclosed requests to BIG-IP iControl REST can lead to information leak of user account names. Note: Software versions which have reached End of Technical…
PriorityP420medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.30%
22.0th percentile
Undisclosed requests to BIG-IP iControl REST can lead to information leak of user account names. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected
88 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip | >= 15.1.0 < * | * |
| f5 | big-ip | >= 16.1.0 < 16.1.5 | 16.1.5 |
| f5 | big-ip | >= 17.1.0 < 17.1.1 | 17.1.1 |
| f5 | big-ip_aam | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | 15.1.0 – 15.1.1 | — |
| f5 | big-ip_access_policy_manager | >= 16.1.0 < 16.1.5 | 16.1.5 |
| f5 | big-ip_advanced_firewall_manager | — | — |
| f5 | big-ip_advanced_firewall_manager | 15.1.0 – 15.1.1 | — |
| f5 | big-ip_advanced_firewall_manager | >= 16.1.0 < 16.1.5 | 16.1.5 |
| f5 | big-ip_advanced_waf | — | — |
| f5 | big-ip_advanced_web_application_firewall | — | — |
| f5 | big-ip_advanced_web_application_firewall | 15.1.0 – 15.1.1 | — |
| f5 | big-ip_advanced_web_application_firewall | >= 16.1.0 < 16.1.5 | 16.1.5 |
| f5 | big-ip_afm | — | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | 15.1.0 – 15.1.1 | — |
| f5 | big-ip_analytics | >= 16.1.0 < 16.1.5 | 16.1.5 |
| f5 | big-ip_apm | — | — |
| f5 | big-ip_application_acceleration_manager | — | — |
| f5 | big-ip_application_acceleration_manager | 15.1.0 – 15.1.1 | — |
| f5 | big-ip_application_acceleration_manager | >= 16.1.0 < 16.1.5 | 16.1.5 |
| f5 | big-ip_application_security_manager | — | — |
| f5 | big-ip_application_security_manager | 15.1.0 – 15.1.1 | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv4.05.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
F5
CVE-2024-41723: Undisclosed requests to BIG-IP iControl REST can lead to information leak of user account names
vendor_f5·2024-08-14·CVSS 4.3
CVE-2024-41723 [MEDIUM] CWE-200 CVE-2024-41723: Undisclosed requests to BIG-IP iControl REST can lead to information leak of user account names
CVE-2024-41723: Undisclosed requests to BIG-IP iControl REST can lead to information leak of user account names
Undisclosed requests to BIG-IP iControl REST can lead to information leak of user account names. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Products: BIG-IP AAM, BIG-IP AFM, BIG-IP APM, BIG-IP ASM, BIG-IP AVR, BIG-IP Advanced WAF, BIG-IP Analytics, BIG-IP CGNAT, BIG-IP DHD, BIG-IP DNS, BIG-IP Edge Gateway, BIG-IP FPS, BIG-IP GTM, BIG-IP LTM, BIG-IP Link Controller, BIG-IP PEM, BIG-IP SSLO, BIG-IP WebAccelerator, BIG-IP WebSafe, Big-Ip Automation Toolchain, Big-Ip Container Ingress Services, iControl REST
Affected Versions: 15.1.0 - 15.1.1; 16.1.0 - 16.1.5; 17.1.0
F5 Advisory Articles: K10438187
F5 References: https://m
Red Hat
etcd: Incomplete fix for CVE-2022-41723 in OpenStack Platform
vendor_redhat·2024-05-06·CVSS 7.5
CVE-2024-4436 [HIGH] CWE-400 etcd: Incomplete fix for CVE-2022-41723 in OpenStack Platform
etcd: Incomplete fix for CVE-2022-41723 in OpenStack Platform
The etcd package distributed with the Red Hat OpenStack platform has an incomplete fix for CVE-2022-41723. This issue occurs because the etcd package in the Red Hat OpenStack platform is using http://golang.org/x/net/http2 instead of the one provided by Red Hat Enterprise Linux versions, meaning it should be updated at compile time instead.
The etcd package distributed with the Red Hat OpenStack platform has an incomplete fix for CVE-2022-41723. This issue occurs because the etcd package in the Red Hat OpenStack platform is using http://golang.org/x/net/http2 instead of the one provided by Red Hat Enterprise Linux versions, meaning it should be updated at compile time instead.
Statement: The Red Hat OpenStack 17.1 is not affe
GHSA
GHSA-4w7w-2j69-jj95: Undisclosed requests to BIG-IP iControl REST can lead to information leak of user account names
ghsa_unreviewed·2024-08-14
CVE-2024-41723 [MEDIUM] CWE-200 GHSA-4w7w-2j69-jj95: Undisclosed requests to BIG-IP iControl REST can lead to information leak of user account names
Undisclosed requests to BIG-IP iControl REST can lead to information leak of user account names. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-08-14
Published