K10438187: BIG-IP iControl REST vulnerability CVE-2024-41723
Discription
Security Advisory Description Undisclosed requests to BIG-IP iControl REST can lead to an information leak of user account names. (CVE-2024-41723) Impact This vulnerability allows for a remote authenticated attacker with network access to the iControl REST interface, through the BIG-IP management interface and self IP addresses, to view only usernames in the BIG-IP system. There is no data plane exposure; this is a control plane issue…Read More
References
Back to Main