CVE-2024-37028
14.08.2024, 15:15
BIG-IP Next Central Manager may allow an attacker to lock out an account that has never been logged in. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.Enginsight
Vendor | Product | Version |
---|---|---|
f5 | big-ip_next_central_manager | 20.1.0 ≤ 𝑥 < 20.2.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-645 - Overly Restrictive Account Lockout MechanismThe software contains an account lockout protection mechanism, but the mechanism is too restrictive and can be triggered too easily, which allows attackers to deny service to legitimate users by causing their accounts to be locked out.
- CWE-287 - Improper AuthenticationWhen an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.