Known vulnerabilities in BIG-IP Next Central Manager

Software CPE: cpe:2.3:a:f5_networks:big-ip_next_central_manager:*:*:*:*:*:*:*:*
Total vulnerabilities: 19
Public exploits: 4
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting BIG-IP Next Central Manager BIG-IP Next Central Manager is affected by 19 known vulnerabilities: 3 high, 9 medium, 7 low Critical High Medium Low

Vulnerabilities (19)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU104034 - Improper input validation
CVE-2025-26466
CWE-20 Medium
Available
No
- 18.02.2025 SB2025021815
SB2025021830
SB2025021840
and 25 more
#VU103725 - Information Exposure Through Log Files
CVE-2025-23413
CWE-532 Low
No
No
20.3.0 07.02.2025 SB2025020742
#VU103716 - Improper input validation
CVE-2025-24319
CWE-20 Medium
No
No
20.3.0 07.02.2025 SB2025020733
#VU96745 - Incorrect Regular Expression
CVE-2024-6232
CWE-185 Medium
No
No
20.3.0 03.09.2024 SB2024090377
SB2024090927
SB2024091048
and 145 more
#VU96043 - Information Exposure Through Log Files
CVE-2024-41719
CWE-532 Low
No
No
20.2.1 15.08.2024 SB2024081525
#VU96041 - Overly Restrictive Account Lockout Mechanism
CVE-2024-37028
CWE-645 Medium
No
No
20.2.1 15.08.2024 SB2024081523
#VU96036 - Insufficient Session Expiration
CVE-2024-39809
CWE-613 Medium
No
No
20.2.0 15.08.2024 SB2024081519
#VU94841 - Out-of-bounds read
CVE-2024-41091
CWE-125 Low
No
No
20.3.0 29.07.2024 SB2024072937
SB2024080967
SB2024080969
and 70 more
#VU94840 - Out-of-bounds read
CVE-2024-41090
CWE-125 Low
No
No
20.3.0 29.07.2024 SB2024072936
SB2024080967
SB2024080969
and 86 more
#VU89294 - Improper Certificate Validation
CVE-2024-33612
CWE-295 Medium
No
No
20.2.0 09.05.2024 SB2024050926
#VU89293 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2024-32049
CWE-300 Medium
No
No
20.1.0 09.05.2024 SB2024050927
#VU89292 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-26026
CWE-89 High
Available
No
20.2.0 09.05.2024 SB2024050926
SB2025030416
#VU89291 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-21793
CWE-89 High
No
No
20.2.0 09.05.2024 SB2024050926
#VU87499 - Resource exhaustion
CVE-2024-26602
CWE-400 Low
No
No
- 13.03.2024 SB2024031336
SB2024031363
SB2024031375
and 58 more
#VU87374 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2024-2193
CWE-362 Low
No
No
- 12.03.2024 SB20240312315
SB2024031401
SB2024031501
and 13 more
#VU87326 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2024-24786
CWE-835 Medium
No
No
- 11.03.2024 SB2024031115
SB2024031435
SB2024031555
and 134 more
#VU84789 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-51385
CWE-78 Medium
Available
No
- 26.12.2023 SB2023121905
SB2023122710
SB2023122801
and 65 more
#VU83900 - Exposure of sensitive information to an unauthorized actor
CVE-2023-46218
CWE-200 Low
No
No
20.1.0 06.12.2023 SB2023120612
SB2023120644
SB2023120661
and 87 more
#VU82544 - Authentication Bypass Using an Alternate Path or Channel
CVE-2023-46747
CWE-288 High
Available
Exploited
- 27.10.2023 SB2023102726
SB2024080142