PT-2024-19382 · F5 · Big-Ip
Published
2024-02-14
·
Updated
2025-09-05
·
CVE-2024-22389
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
The affected software is BIG-IP, specifically when deployed in high availability (HA) mode.
The issue arises when an iControl REST API token is updated, and this change is not synchronized with the peer device.
An exploit for this issue is available.
The BIG-IP software is affected when deployed in high availability mode and an iControl REST API token is updated, causing the change to not sync with the peer device.
Note that software versions which have reached End of Technical Support (EoTS) are not evaluated.
#BIGIP #iControl #RESTAPI #HighAvailability #Cybersecurity #Infosec #Hacker #NVD #Mitre
Fix
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Big-Ip