Vulnerabilities > CVE-2024-24966 - Incorrect Authorization vulnerability in F5 F5Os-A and F5Os-C

047910
CVSS 5.5 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
local
low complexity
f5
CWE-863

Summary

When LDAP remote authentication is configured on F5OS, a remote user without an assigned role will be incorrectly authorized.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Vulnerable Configurations

Part Description Count
OS
F5
3

Common Weakness Enumeration (CWE)