CVE-2024-23976
BIG-IP Appliance mode iAppsLX vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
When running in Appliance mode, an authenticated attacker assigned the Administrator role may be able to bypass Appliance
mode restrictions utilizing iAppsLX templates on a BIG-IP system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Cuando se ejecuta en modo Dispositivo, un atacante autenticado al que se le haya asignado la función de Administrador puede eludir las restricciones del modo Dispositivo utilizando plantillas iAppsLX en un sistema BIG-IP. Nota: Las versiones de software que han llegado al final del soporte técnico (EoTS) no se evalúan
When running in Appliance mode, an authenticated attacker assigned the Administrator role may be able to bypass Appliance mode restrictions utilizing iAppsLX templates on a BIG-IP system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-02-01 CVE Reserved
- 2024-02-14 CVE Published
- 2024-08-01 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-266: Incorrect Privilege Assignment
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://my.f5.com/manage/s/article/K91054692 | 2024-02-14 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
F5 Search vendor "F5" | BIG-IP Search vendor "F5" for product "BIG-IP" | >= 17.1.0 < 17.1.1 Search vendor "F5" for product "BIG-IP" and version " >= 17.1.0 < 17.1.1" | en |
Affected
| ||||||
F5 Search vendor "F5" | BIG-IP Search vendor "F5" for product "BIG-IP" | >= 16.1.0 < 16.1.4 Search vendor "F5" for product "BIG-IP" and version " >= 16.1.0 < 16.1.4" | en |
Affected
| ||||||
F5 Search vendor "F5" | BIG-IP Search vendor "F5" for product "BIG-IP" | >= 15.1.0 < 15.1.9 Search vendor "F5" for product "BIG-IP" and version " >= 15.1.0 < 15.1.9" | en |
Affected
|