CISA: Hackers abuse F5 BIG-IP cookies to map internal servers

Share:

CISA is warning that threat actors have been observed abusing unencrypted persistent F5 BIG-IP cookies to identify and target other internal devices on the targeted network.

By mapping out internal devices, threat actors can potentially identify vulnerable devices on the network as part of the planning stages in cyberattacks.

“CISA has observed cyber threat actors leveraging unencrypted persistent cookies managed by the F5 BIG-IP Local Traffic Manager (LTM) module to enumerate other non-internet facing devices on the network,” warns CISA.

“A malicious cyber actor could leverage the information gathered from unencrypted persistence cookies to infer or identify additional network resources and potentially exploit vulnerabilities found in other devices present on the network.”

F5 persistent sessions cookies

F5 BIG-IP is a suite of application delivery and traffic management tools for load-balancing web applications and for providing security.

One of its core modules is the Local Traffic Manager (LTM) module, which provides traffic management and load balancing to distribute network traffic across multiple servers. Using this feature, customers optimize their load-balanced server resources and high availability.

The Local Traffic Manager (LTM) module within the product uses persistence cookies that help maintain session consistency by directing traffic from clients (web browsers) to the same backend server each time, which is crucial for load balancing.

“Cookie persistence enforces persistence using HTTP cookies,” explains F5’s documentation.

“As with all persistence modes, HTTP cookies ensure that requests from the same client are directed to the same pool member after the BIG-IP system initially load-balances them. If the same pool member is not available, the system makes a new load balancing decision.”

These cookies are unencrypted by default, likely to maintain operational integrity with legacy configurations or due to performance considerations.

Starting in version 11.5.0 and onward, administrators were given a new “Required” option to enforce encryption on all cookies. Those who opted not to enable it were exposed to security risks.

However, these cookies contain encoded IP addresses, port numbers, and load-balancing setups of the internal load-balanced servers.

For years, cybersecurity researchers have shared how the unencrypted cookies can be abused to find previously hidden internal servers or possible unknown exposed servers that can be scanned for vulnerabilities and used to breach an internal network. A Chrome extension was also released for decoding these cookies to aid BIG-IP administrators troubleshoot connections.

According to CISA, threat actors are already tapping into this potential, exploiting lax configurations for network discovery.

CISA recommends that F5 BIG-IP administrators review the vendor’s instructions (also here) on how to encrypt these persistent cookies.

Note that a midpoint “Preferred” configuration option generates encrypted cookies but also allows the system to accept unencrypted cookies. This setting can be used during the migration phase to allow previously issued cookies to continue to work before enforcing encrypted cookies.

When set to “Required,” all persistent cookies are ciphered using strong AES-192 encryption.

CISA also notes that F5 has developed a diagnostic tool named ‘BIG-IP iHealth’ designed to detect misconfigurations on the product and warn admins about them.

Bill Toulas

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
1:28 pm, Jun 26, 2025
weather icon 23°C
L: 21° | H: 24°
light rain
Humidity: 70 %
Pressure: 1010 mb
Wind: 15 mph SW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0.3 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:44 am
Sunset: 9:21 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
21° | 24°°C 0.24 mm 24% 17 mph 61 % 1018 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
16° | 28°°C 0 mm 0% 13 mph 61 % 1021 mb 0 mm/h
Sat Jun 28 10:00 pm
weather icon
17° | 28°°C 0.2 mm 20% 10 mph 88 % 1025 mb 0 mm/h
Sun Jun 29 10:00 pm
weather icon
19° | 32°°C 0 mm 0% 6 mph 82 % 1025 mb 0 mm/h
Mon Jun 30 10:00 pm
weather icon
21° | 34°°C 0.2 mm 20% 12 mph 59 % 1019 mb 0 mm/h
Today 4:00 pm
weather icon
23° | 23°°C 0.24 mm 24% 17 mph 61 % 1011 mb 0 mm/h
Today 7:00 pm
weather icon
21° | 22°°C 0 mm 0% 13 mph 47 % 1013 mb 0 mm/h
Today 10:00 pm
weather icon
17° | 17°°C 0 mm 0% 10 mph 47 % 1018 mb 0 mm/h
Tomorrow 1:00 am
weather icon
16° | 16°°C 0 mm 0% 8 mph 57 % 1020 mb 0 mm/h
Tomorrow 4:00 am
weather icon
16° | 16°°C 0 mm 0% 6 mph 61 % 1020 mb 0 mm/h
Tomorrow 7:00 am
weather icon
17° | 17°°C 0 mm 0% 8 mph 59 % 1021 mb 0 mm/h
Tomorrow 10:00 am
weather icon
22° | 22°°C 0 mm 0% 11 mph 52 % 1021 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
26° | 26°°C 0 mm 0% 12 mph 46 % 1020 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€91,720.69
0.15%
Ethereum(ETH)
€2,091.35
0.89%
Tether(USDT)
€0.86
-0.02%
XRP(XRP)
€1.86
-1.05%
Solana(SOL)
€122.74
-1.61%
USDC(USDC)
€0.85
-0.01%
Dogecoin(DOGE)
€0.137963
-2.20%
Shiba Inu(SHIB)
€0.000009
-2.00%
Pepe(PEPE)
€0.000008
-6.25%
Scroll to Top