* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Saturday, May 9, 2026
Earth-News
  • Home
  • Business
  • Entertainment

    From Taylor Swift to the Oscars, 400-year-old ‘Hamlet’ flourishes in the age of TikTok – Audacy

    How Social Network Currency is Launching a Grad’s Career in Entertainment Journalism

    Live Nation Entertainment Stock Soars 7% Today – Key Insights You Can’t Miss

    AMC Entertainment Grapples with Rapid Share Dilution as Market Pressures Mount

    ARRI Unveils Omnibar LED Linear Fixture Revolutionizing Film, Live Entertainment, and Content Creation

    NCUHS Dance and Drama Shine at Exciting 4th Annual Cabaret Celebration

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology

    NCR Voyix Set to Dazzle at the 21st Annual Needham Technology, Media & Consumer Conference

    Danville High School’s Automotive Technology Classes Get a Boost with New Vehicle from Public School Foundation

    Seagate Technology Holdings PLC $STX Position Increased by Swedbank AB – MarketBeat

    Retail CIOs Risk Wasted AI Spend Without Data Flow Visibility Across the Technology Stack, Finds Info-Tech Research Group – PR Newswire

    Inside China’s High-Tech Ambush: Unveiling the Rise of the ‘Silicon Curtain

    Global Millennial Capital Raises $100 Million to Fuel Emerging Tech Leaders in Underserved Mid-Cap Markets

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment

    From Taylor Swift to the Oscars, 400-year-old ‘Hamlet’ flourishes in the age of TikTok – Audacy

    How Social Network Currency is Launching a Grad’s Career in Entertainment Journalism

    Live Nation Entertainment Stock Soars 7% Today – Key Insights You Can’t Miss

    AMC Entertainment Grapples with Rapid Share Dilution as Market Pressures Mount

    ARRI Unveils Omnibar LED Linear Fixture Revolutionizing Film, Live Entertainment, and Content Creation

    NCUHS Dance and Drama Shine at Exciting 4th Annual Cabaret Celebration

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology

    NCR Voyix Set to Dazzle at the 21st Annual Needham Technology, Media & Consumer Conference

    Danville High School’s Automotive Technology Classes Get a Boost with New Vehicle from Public School Foundation

    Seagate Technology Holdings PLC $STX Position Increased by Swedbank AB – MarketBeat

    Retail CIOs Risk Wasted AI Spend Without Data Flow Visibility Across the Technology Stack, Finds Info-Tech Research Group – PR Newswire

    Inside China’s High-Tech Ambush: Unveiling the Rise of the ‘Silicon Curtain

    Global Millennial Capital Raises $100 Million to Fuel Emerging Tech Leaders in Underserved Mid-Cap Markets

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

New BIG-IP Next Central Manager bugs allow device takeover

May 9, 2024
in Technology
New BIG-IP Next Central Manager bugs allow device takeover
Share on FacebookShare on Twitter

F5

F5 has fixed two high-severity BIG-IP Next Central Manager vulnerabilities, which can be exploited to gain admin control and create hidden rogue accounts on any managed assets.

Next Central Manager allows administrators to control on-premises or cloud BIG-IP Next instances and services via a unified management user interface.

The flaws are an SQL injection vulnerability (CVE-2024-26026) and an OData injection vulnerability (CVE-2024-21793) found in the BIG-IP Next Central Manager API that would allow unauthenticated attackers to execute malicious SQL statements on unpatched devices remotely.

SQL injection attacks involve injecting malicious SQL queries into input fields or parameters in database queries. This exploits vulnerabilities in the application’s security and allows unintended SQL commands to execute, resulting in unauthorized access, data breaches, and system takeovers.

Supply chain security firm Eclypsium, which reported the flaws and shared a proof-of-concept exploit on Wednesday, says that rogue accounts created after compromising an unpatched instance are not visible from Next Central Manager and can thus be used for malicious persistence within a victim’s environment.

“The management console of the Central Manager can be remotely exploited by any attacker able to access the administrative UI via CVE 2024-21793 or CVE 2024-26026. This would result in full administrative control of the manager itself,” Eclypsium says.

“Attackers can then take advantage of the other vulnerabilities to create new accounts on any BIG-IP Next asset managed by the Central Manager. Notably, these new malicious accounts would not be visible from the Central Manager itself.”

Potential attack pathsPotential attack paths (Eclypsium)

PoC exploit and temporary mitigation available

According to F5’s recommendations, administrators who can’t immediately install today’s security updates should restrict Next Central Manager access to trusted users over a secure network to mitigate attack risks.

Luckily, according to Eclypsium, there is no evidence that the two security vulnerabilities have been exploited in attacks.

While adoption rates for F5’s BIG-IP Next Central Manager are currently unknown, Shodan currently tracks over 10,000 F5 BIG-IP devices with management ports exposed online.

In November, F5 warned customers that “skilled” attackers were exploiting two critical BIG-IP vulnerabilities (CVE-2023-46747 and CVE-2023-46748) fixed one month before to hack into unpatched devices, executing malicious code and erasing signs of the breach.

Two years ago, CISA also cautioned of widespread exploitation of another F5 BIG-IP flaw (CVE-2022-1388)—also allowing device takeover—across government and private sector networks and shared guidance to block the ongoing attacks.

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : BleepingComputer – https://www.bleepingcomputer.com/news/security/new-big-ip-next-central-manager-bugs-allow-device-takeover/

Tags: BIG-IPCentraltechnology
Previous Post

Education, health fees among key concerns

Next Post

Stack Overflow suspends user for editing posts in OpenAI protest

Opinion: The Regional Ecological Summit and the Making of a Central Asian Voice – The Times Of Central Asia

May 8, 2026

Revolutionizing Mexican Poultry Science: Breakthroughs and Innovations Driving the Future

May 8, 2026

Inside the ‘Beehive’ School: The Secrets Behind Utah’s Reign as the Top High School

May 8, 2026

State Employees Speak Out Against Removing Blue Cross from Kansas Health Plan

May 8, 2026

How Adults with Consistent Bedtimes Are Unlocking the Ultimate Self-Care Secret

May 8, 2026

Trump Blasts $1,000 World Cup Tickets: ‘I Wouldn’t Pay That Either, Honestly

May 8, 2026

U.S. Economy Booms with Double the Job Growth in April: Key Implications for the Stock Market

May 8, 2026

From Taylor Swift to the Oscars, 400-year-old ‘Hamlet’ flourishes in the age of TikTok – Audacy

May 8, 2026

Spencer Pratt compares his fledgling political career to Obama’s national rise: “He had no experience running the whole entire country” – CBS News

May 8, 2026

NCR Voyix Set to Dazzle at the 21st Annual Needham Technology, Media & Consumer Conference

May 8, 2026

Categories

Archives

May 2026
M T W T F S S
 123
45678910
11121314151617
18192021222324
25262728293031
« Apr    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (1,206)
  • Economy (1,227)
  • Entertainment (22,103)
  • General (21,406)
  • Health (10,260)
  • Lifestyle (1,238)
  • News (22,149)
  • People (1,228)
  • Politics (1,246)
  • Science (16,441)
  • Sports (21,724)
  • Technology (16,210)
  • World (1,217)

Recent News

Opinion: The Regional Ecological Summit and the Making of a Central Asian Voice – The Times Of Central Asia

May 8, 2026

Revolutionizing Mexican Poultry Science: Breakthroughs and Innovations Driving the Future

May 8, 2026
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version