First published: Wed Aug 14 2024(Updated: )
The BIG-IP Next Central Manager user session refresh token does not expire when a user logs out.
Affected Software | Affected Version | How to fix |
---|---|---|
F5 BIG-IP Next Central Manager | =20.1.0 | 20.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of F5-K000140111 is classified as critical due to the potential for unauthorized access after user logout.
To fix F5-K000140111, it is recommended to apply the latest firmware updates provided by F5 to ensure proper session handling.
F5-K000140111 affects the F5 BIG-IP Next Central Manager versions 20.1.0 and 20.2.0.
With F5-K000140111, attackers can potentially exploit the non-expiring session token to maintain access to the system even after a user has logged out.
Currently, there are no recommended workarounds for F5-K000140111, so applying the necessary patches is crucial.