CVE Vulnerabilities

CVE-2024-23306

Insufficiently Protected Credentials

Published: Feb 14, 2024 | Modified: Jan 23, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability exists in BIG-IP Next CNF and SPK systems that may allow access to undisclosed sensitive files.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

Name Vendor Start Version End Version
Big-ip_next_cloud-native_network_functions F5 1.1.0 (including) 1.2.0 (excluding)

Potential Mitigations

References