F5 Security Updates – 30 May 2024

F5 has released security updates to address several vulnerabilities in NGINX Plus and NGINX Open Source.

The addressed vulnerabilities could allow the remote attacker to obtain sensitive information or perform denial of service attacks on the affected system.

Sample of the addressed vulnerabilities:

1. F5 NGINX Plus and NGINX Open Source Denial of Service Vulnerability (CVE-2024-32760):

  • CVSS: 6.5
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Denial of Service

2. F5 NGINX Plus and NGINX Open Source Information Disclosure Vulnerability (CVE-2024-34161):

  • CVSS: 5.3
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Obtain Information
Vulnerabilities
  • CVE-2024-32760
  • CVE-2024-34161
  • CVE-2024-35200
  • CVE-2024-31079
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

F5 Security Advisory

References