CVE Vulnerabilities

CVE-2024-23976

Incorrect Privilege Assignment

Published: Feb 14, 2024 | Modified: Sep 05, 2025
CVSS 3.x
6
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

When running in Appliance mode, an authenticated attacker assigned the Administrator role may be able to bypass Appliance mode restrictions utilizing iAppsLX templates on a BIG-IP system.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

Weakness

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
Big-ip_access_policy_managerF515.1.0 (including)15.1.9 (excluding)
Big-ip_access_policy_managerF516.1.0 (including)16.1.4 (excluding)
Big-ip_access_policy_managerF517.1.0 (including)17.1.0 (including)

Potential Mitigations

References