PT-2024-19382 · F5 · Big-Ip

Published

2024-02-14

·

Updated

2025-09-05

·

CVE-2024-22389

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The affected software is BIG-IP, specifically when deployed in high availability (HA) mode. The issue arises when an iControl REST API token is updated, and this change is not synchronized with the peer device. An exploit for this issue is available. The BIG-IP software is affected when deployed in high availability mode and an iControl REST API token is updated, causing the change to not sync with the peer device. Note that software versions which have reached End of Technical Support (EoTS) are not evaluated. #BIGIP #iControl #RESTAPI #HighAvailability #Cybersecurity #Infosec #Hacker #NVD #Mitre

Fix

Insufficient Session Expiration

Weakness Enumeration

Related Identifiers

CVE-2024-22389

Affected Products

Big-Ip