
CVE-2024-27202 – BIG-IP TMUI XSS vulnerability
https://notcve.org/view.php?id=CVE-2024-27202
08 May 2024 — A DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Existe una vulnerabilidad de cross site scripting (XSS) basada en DOM en una página no revelada de la utilidad de configuración BIG-IP que permite a un atacante ejecutar JavaScript en el contexto del usuario a... • https://my.f5.com/manage/s/article/K000138520 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2024-28883 – BIG-IP APM browser network access VPN client vulnerability
https://notcve.org/view.php?id=CVE-2024-28883
08 May 2024 — An origin validation vulnerability exists in BIG-IP APM browser network access VPN client for Windows, macOS and Linux which may allow an attacker to bypass F5 endpoint inspection. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Existe una vulnerabilidad de validación de origen en el cliente VPN de acceso a la red del navegador BIG-IP APM para Windows, macOS y Linux que puede permitir a un atacante eludir la inspección del endpoint F5. Nota: Las versiones de sof... • https://my.f5.com/manage/s/article/K000138744 • CWE-346: Origin Validation Error •

CVE-2024-21763 – BIG-IP AFM vulnerability
https://notcve.org/view.php?id=CVE-2024-21763
14 Feb 2024 — When BIG-IP AFM Device DoS or DoS profile is configured with NXDOMAIN attack vector and bad actor detection, undisclosed queries can cause the Traffic Management Microkernel (TMM) to terminate. NOTE: Software versions which have reached End of Technical Support (EoTS) are not evaluated Cuando el perfil DoS o DoS del dispositivo BIG-IP AFM se configura con el vector de ataque NXDOMAIN y la detección de malos actores, las consultas no reveladas pueden provocar la finalización del Microkernel de gestión de trá... • https://my.f5.com/manage/s/article/K000137521 • CWE-476: NULL Pointer Dereference •

CVE-2024-23805 – F5 Application Visibility and Reporting module and BIG-IP Advanced WAF/ASM vulnerability
https://notcve.org/view.php?id=CVE-2024-23805
14 Feb 2024 — Undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. For the Application Visibility and Reporting module, this may occur when the HTTP Analytics profile with URLs enabled under Collected Entities is configured on a virtual server and the DB variables avr.IncludeServerInURI or avr.CollectOnlyHostnameFromURI are enabled. For BIG-IP Advanced WAF and ASM, this may occur when either a DoS or Bot Defense profile is configured on a virtual server and the DB variables avr.IncludeSer... • https://my.f5.com/manage/s/article/K000137334 • CWE-131: Incorrect Calculation of Buffer Size •

CVE-2024-23603 – BIG-IP Advanced WAF and ASM Configuration utility vulnerability
https://notcve.org/view.php?id=CVE-2024-23603
14 Feb 2024 — An SQL injection vulnerability exists in an undisclosed page of the BIG-IP Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated Existe una vulnerabilidad de inyección SQL en una página no divulgada de la utilidad de configuración BIG-IP. Nota: Las versiones de software que han llegado al final del soporte técnico (EoTS) no se evalúan • https://my.f5.com/manage/s/article/K000138047 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2024-24775 – BIG-IP TMM vulnerability
https://notcve.org/view.php?id=CVE-2024-24775
14 Feb 2024 — When a virtual server is enabled with VLAN group and SNAT listener is configured, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated Cuando un servidor virtual está habilitado con un grupo VLAN y el escucha SNAT está configurado, el tráfico no divulgado puede hacer que finalice el Microkernel de gestión de tráfico (TMM). Nota: Las versiones de software que han llegado al final del s... • https://my.f5.com/manage/s/article/K000137333 • CWE-476: NULL Pointer Dereference •

CVE-2024-23314 – BIG-IP HTTP/2 vulnerability
https://notcve.org/view.php?id=CVE-2024-23314
14 Feb 2024 — When HTTP/2 is configured on BIG-IP or BIG-IP Next SPK systems, undisclosed responses can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated Cuando HTTP/2 está configurado en sistemas BIG-IP o BIG-IP Next SPK, las respuestas no reveladas pueden provocar la finalización del Microkernel de gestión de tráfico (TMM). Nota: Las versiones de software que han llegado al final del soporte técnico (EoTS) no se eval... • https://my.f5.com/manage/s/article/K000137675 • CWE-908: Use of Uninitialized Resource •

CVE-2024-22093 – Appliance mode iControl REST vulnerability
https://notcve.org/view.php?id=CVE-2024-22093
14 Feb 2024 — When running in appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint on multi-bladed systems. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated Cuando se ejecuta en modo dispositivo, existe una vulnerabilidad de inyección remota de comandos autenticada en un endpoint iControl REST no revelado en sistemas multiblade. Un exploit... • https://my.f5.com/manage/s/article/K000137522 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •

CVE-2024-23979 – BIG-IP SSL Client Certificate LDAP and CRLDP Authentication profiles vulnerability
https://notcve.org/view.php?id=CVE-2024-23979
14 Feb 2024 — When SSL Client Certificate LDAP or Certificate Revocation List Distribution Point (CRLDP) authentication profile is configured on a virtual server, undisclosed requests can cause an increase in CPU resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated Cuando el perfil de autenticación LDAP del certificado de cliente SSL o punto de distribución de lista de revocación de certificados (CRLDP) se configura en un servidor virtual, las solicitudes no d... • https://my.f5.com/manage/s/article/K000134516 • CWE-770: Allocation of Resources Without Limits or Throttling •

CVE-2024-21771 – F5 AFM Signature Matching Vulnerability
https://notcve.org/view.php?id=CVE-2024-21771
14 Feb 2024 — For unspecified traffic patterns, BIG-IP AFM IPS engine may spend an excessive amount of time matching the traffic against signatures, resulting in Traffic Management Microkernel (TMM) restarting and traffic disruption. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated Para patrones de tráfico no especificados, el motor BIG-IP AFM IPS puede dedicar una cantidad excesiva de tiempo a comparar el tráfico con las firmas, lo que provoca el reinicio del microkernel de ge... • https://my.f5.com/manage/s/article/K000137595 • CWE-770: Allocation of Resources Without Limits or Throttling •