CVE-2024-22389: BIG-IP iControl REST API Vulnerability
When BIG-IP is deployed in high availability (HA) and an iControl REST API token is updated, the change does not sync to the peer device.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.1.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.1.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.1.9
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22389?
CVE-2024-22389 has not been assigned a specific severity rating, but it poses a risk in high availability deployments of F5 BIG-IP systems when API tokens are not synchronized.
How do I fix CVE-2024-22389?
To resolve CVE-2024-22389, ensure that the iControl REST API token is updated consistently across all peer devices in the high availability configuration.
What versions of F5 BIG-IP are affected by CVE-2024-22389?
CVE-2024-22389 affects F5 BIG-IP versions 17.1.0, 16.1.0 through 16.1.4, and 15.1.0 through 15.1.9.
What are the implications of CVE-2024-22389 for F5 BIG-IP users?
Users of F5 BIG-IP in high availability configurations may experience synchronization issues with API tokens, which could potentially affect their security posture.
Is there a workaround for CVE-2024-22389?
While no official workaround is provided for CVE-2024-22389, manual synchronization of API tokens may mitigate synchronization discrepancies.