CVE-2024-32761
MEDIUMDescription
Under certain conditions, a data leak may occur in the Traffic Management Microkernels (TMMs) of BIG-IP tenants running on VELOS and rSeries platforms. This leak occurs randomly and cannot be deliberately triggered. If it occurs, it may leak up to 64 bytes of non-contiguous randomized bytes. Under rare conditions, this may lead to a TMM restart, affecting availability. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Is your site exposed to CVE-2024-32761?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| f5 | big-ip_access_policy_manager |
| f5 | big-ip_advanced_firewall_manager |
| f5 | big-ip_advanced_web_application_firewall |
| f5 | big-ip_analytics |
| f5 | big-ip_application_acceleration_manager |
| f5 | big-ip_application_security_manager |
| f5 | big-ip_application_visibility_and_reporting |
| f5 | big-ip_automation_toolchain |
| f5 | big-ip_carrier-grade_nat |
| f5 | big-ip_container_ingress_services |
| f5 | big-ip_ddos_hybrid_defender |
| f5 | big-ip_domain_name_system |
| f5 | big-ip_edge_gateway |
| f5 | big-ip_fraud_protection_service |
| f5 | big-ip_global_traffic_manager |
| f5 | big-ip_link_controller |
| f5 | big-ip_local_traffic_manager |
| f5 | big-ip_policy_enforcement_manager |
| f5 | big-ip_ssl_orchestrator |
| f5 | big-ip_webaccelerator |
| f5 | big-ip_websafe |
References
Frequently Asked Questions
What is CVE-2024-32761? +
How severe is CVE-2024-32761? +
What products are affected by CVE-2024-32761? +
How do I check if I'm vulnerable to CVE-2024-32761? +
Related Vulnerabilities
CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could allow local attackers to …
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in warmcat libwebsockets allows Pointer Manipulation, potentially leading …
Buffer overflow vulnerability in Immunity Debugger affecting version 1.85, its exploitation could allow a local attacker to execute arbitrary code, …
z2d is a pure Zig 2D graphics library. Versions of z2d after `0.5.1` and up to and including `0.6.0`, when …
A vulnerability has been found in TP-Link TL-WR940N V4 and TL-WR841N V11. Affected by this issue is some unknown functionality …
A stack-based buffer overflow vulnerability exists in Easy File Sharing HTTP Server version 7.2. The flaw is triggered when a …