CVE Vulnerabilities

CVE-2024-37028

Overly Restrictive Account Lockout Mechanism

Published: Aug 14, 2024 | Modified: Aug 20, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

BIG-IP Next Central Manager may allow an attacker to lock out an account that has never been logged in.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Weakness

The product contains an account lockout protection mechanism, but the mechanism is too restrictive and can be triggered too easily, which allows attackers to deny service to legitimate users by causing their accounts to be locked out.

Affected Software

Name Vendor Start Version End Version
Big-ip_next_central_manager F5 20.1.0 (including) 20.2.1 (excluding)

Potential Mitigations

References