CVE-2024-32049
BIG-IP Next Central Manager (CM) may allow an unauthenticated, remote attacker to obtain the BIG-IP Next LTM/WAF instance credentials. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.4
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS probability
- 0.55%
- CWE
- CWE-300
- Published
- 2024-05-08
- Last modified
- 2026-03-13
Affected products
- F5 BIG-IP Next Central Manager
Weakness type
Related vulnerabilities
- CVE-2026-84197 — In Eclipse Ditto's Node.js JavaScript client, all released versions of...
- CVE-2026-74232 — Zbtlink MQWrt yunmgrd Cloud C2 Implant
- CVE-2026-12991 — Multiple vulnerabilities in Ghost Robotics' Vision 60
- CVE-2025-40770 — A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions)....
- CVE-2025-54792 — LocalSend is Vulnerable to Man-in-the-Middle Attacks, Leading to File Interception
- CVE-2024-50568 — A channel accessible by non-endpoint vulnerability [CWE-300] in Fortinet FortiOS version 7.4.0...
- CVE-2025-20122 — Cisco Catalyst SD-WAN Manager Privilege Escalation Vulnerability
- CVE-2024-50565 — A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in...