Open-Source Security Intelligence

Know every vulnerability
before it knows you.

DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.

Search

NCSC-2025-0041

Published Feb 7, 2025·Last modified Feb 11, 2025
Description
Feiten

F5 heeft kwetsbaarheden verholpen in BIG-IP.

Interpretaties

Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade:

  • Denial-of-Service (DoS)
  • Omzeilen van een beveiligingsmaatregel
  • Uitvoer van willekeurige code (Root/admin)
  • Uitvoer van willekeurige code (Gebruiker)
  • Toegang tot gevoelige gegevens
Oplossingen

F5 heeft updates uitgebracht om de kwetsbaarheden te verhelpen. Zie bijgevoegde referenties voor meer informatie.

Kans

medium

Schade

high

CWE-772

Missing Release of Resource after Effective Lifetime

CWE-367

Time-of-check Time-of-use (TOCTOU) Race Condition

CWE-311

Missing Encryption of Sensitive Data

CWE-426

Untrusted Search Path

CWE-345

Insufficient Verification of Data Authenticity

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

CWE-190

Integer Overflow or Wraparound

CWE-693

Protection Mechanism Failure

CWE-125

Out-of-bounds Read

CWE-401

Missing Release of Memory after Effective Lifetime

CWE-476

NULL Pointer Dereference

CWE-400

Uncontrolled Resource Consumption

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CWE-787

Out-of-bounds Write

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

CWE-20

Improper Input Validation

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Scan your project

Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.

Checkout DevGuard