### [CVE-2024-39809](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-39809) ![](https://img.shields.io/static/v1?label=Product&message=BIG-IP%20Next%20Central%20Manager&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=20.1.0%3C%2020.2.0%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-613%20Insufficient%20Session%20Expiration&color=brighgreen) ### Description The Central Manager user session refresh token does not expire when a user logs out.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated ### POC #### Reference No PoCs from references. #### Github - https://github.com/fkie-cad/nvd-json-data-feeds