F5-K000140111: High severity f5 big-ip next central manager vulnerability
Published Aug 14, 2024
·Updated
The BIG-IP Next Central Manager user session refresh token does not expire when a user logs out.
Affected Software
1 affected componentFixes available
F5 BIG-IP Next Central Manager=20.1.0
20.2.0
Event History
Aug 14, 2024
Advisory Published
via F5·01:22 PM
Frequently Asked Questions
1
What is the severity of F5-K000140111?
The severity of F5-K000140111 is classified as critical due to the potential for unauthorized access after user logout.
2
How do I fix F5-K000140111?
To fix F5-K000140111, it is recommended to apply the latest firmware updates provided by F5 to ensure proper session handling.
3
What systems are affected by F5-K000140111?
F5-K000140111 affects the F5 BIG-IP Next Central Manager versions 20.1.0 and 20.2.0.
4
What can attackers do with F5-K000140111?
With F5-K000140111, attackers can potentially exploit the non-expiring session token to maintain access to the system even after a user has logged out.
5
Is there a workaround for F5-K000140111?
Currently, there are no recommended workarounds for F5-K000140111, so applying the necessary patches is crucial.