Big Ip Next Central Manager
Vendor:
First CVE: May 8, 2024 · Active for 2 years
12
Total CVEs
More Total CVEs than 91% of tracked products
6.0
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 37% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Big Ip Next Central Manager over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 8, 2024
2 years ago
Most Recent CVE
Aug 13, 2025
349 days ago
CVE Severity & Scoring
Big Ip Next Central Manager12 CVEs
50%
50%
All CVEs353,240 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local2 (16.7%)
Network10 (83.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (83.3%)
High2 (16.7%)
Unknown0 (0.0%)
User Interaction
None10 (83.3%)
Unknown0 (0.0%)
Required2 (16.7%)
Privileges Required
Low1 (8.3%)
High1 (8.3%)
None10 (83.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-26026HIGH An SQL injection vulnerability exists in the BIG-IP Next Central Manager API (URI). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | May 8, 2024 | 7.5 | 28 | NO | NO |
CVE-2024-21793HIGH An OData injection vulnerability exists in the BIG-IP Next Central Manager API (URI). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | May 8, 2024 | 7.5 | 28 | NO | NO |
CVE-2025-36504HIGH When a BIG-IP HTTP/2 httprouter profile is configured on a virtual server, undisclosed responses can cause an increase in memory resource utilization. Note: Software versions whic | May 7, 2025 | 7.5 | 22 | NO | NO |
CVE-2024-39809HIGH The Central Manager user session refresh token does not expire when a user logs out. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | Aug 14, 2024 | 8.8 | 22 | NO | NO |
CVE-2025-54500MEDIUM An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit (HTTP/2 MadeYouReset Att | Aug 13, 2025 | 5.3 | 21 | NO | NO |
CVE-2025-41399HIGH When a Stream Control Transmission Protocol (SCTP) profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Softw | May 7, 2025 | 7.5 | 21 | NO | NO |
CVE-2024-33612MEDIUM An improper certificate validation vulnerability exists in BIG-IP Next Central Manager and may allow an attacker to impersonate an Instance Provider system. Note: Software version | May 8, 2024 | 6.8 | 20 | NO | NO |
CVE-2025-24319MEDIUM When BIG-IP Next Central Manager is running, undisclosed requests to the BIG-IP Next Central Manager API can cause the BIG-IP Next Central Manager Node's Kubernetes service to term | Feb 5, 2025 | 6.5 | 19 | NO | NO |
CVE-2024-32049HIGH BIG-IP Next Central Manager (CM) may allow an unauthenticated, remote attacker to obtain the BIG-IP Next LTM/WAF instance credentials.
Note: Software versions which have reached | May 8, 2024 | 7.4 | 19 | NO | NO |
CVE-2024-41719MEDIUM When generating QKView of BIG-IP Next instance from the BIG-IP Next Central Manager (CM), F5 iHealth credentials will be logged in the BIG-IP Central Manager logs. Note: Software | Aug 14, 2024 | 5.5 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (12 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (12 CVEs).
Media Mentions
Signals from CVEs in this product scope (12 CVEs).
Top CNAs Publishing CVEs For Big Ip Next Central Manager
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 20.3.0 | 1 | 5.3 | 0.5% | 0 | 0 |
| 20.2.1 | 1 | 7.5 | 0.4% | 0 | 0 |
| 20.2.0 | 2 | 7.5 | 0.4% | 0 | 0 |
| 20.1.0 | 1 | 8.8 | 0.4% | 0 | 0 |