F5 BIG-IP Next Central Manager: The Unauthenticated Takeover Bugs
On November 6, 2024, F5 disclosed a pair of critical bugs in BIG-IP Next Central Manager shipped in its SPK fabric: CVE-2024-23327, an unauthenticated privilege-escalation path reachable via REST API, and CVE-2024-23328, a missing-authentication flaw letting attackers create arbitrary administrator accounts. Together they enable full takeover of a management node that itself commands a fleet of application delivery hardware. This account walks both paths, the same-day patches, and the uncomfortable lineage going back to CVE-2022-1388's iControl REST flaw.
