CVE-2024-39809: BIG-IP Next Central Manager vulnerability
The BIG-IP Next Central Manager user session refresh token does not expire when a user logs out.
Other sources
The Central Manager user session refresh token does not expire when a user logs out. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39809?
CVE-2024-39809 has been classified as a vulnerability of medium severity due to the risk of unauthorized access.
How do I fix CVE-2024-39809?
To fix CVE-2024-39809, ensure that you update to the latest supported version of F5 BIG-IP Next Central Manager.
What are the affected software versions for CVE-2024-39809?
CVE-2024-39809 affects F5 BIG-IP Next Central Manager versions 20.1.0 and 20.2.0.
What is the impact of CVE-2024-39809?
The impact of CVE-2024-39809 is that a user's session may remain active even after they log out, potentially allowing an attacker to exploit this.
Is there a workaround for CVE-2024-39809?
Currently, there are no documented workarounds for CVE-2024-39809, and users are advised to upgrade their software instead.