F5 BIG-IP Next Central Manager
cpe:2.3:a:f5:big-ip_next_central_manager:*:*:*:*:*:*:*
- >= 20.2.0, <= 20.2.1
A denial-of-service vulnerability has been identified in F5 BIG-IP Next Central Manager versions 20.2.0 to 20.2.1. When BIG-IP Next Central Manager is active, certain undisclosed requests to its API can lead to the termination of the Kubernetes service on the BIG-IP Next Central Manager Node. This issue affects only the control plane, with no exposure to the data plane.
Exploitation of this vulnerability can cause the BIG-IP Next Central Manager to become unavailable, disrupting management of Kubernetes services.
Users can upgrade to BIG-IP Next Central Manager version 20.3.0 to address this vulnerability. For guidance on managing BIG-IP product hotfixes, refer to the F5 article K13123.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.