Showing 4 vulnerabilities on this page for F5OS-A

Signals CISA KEV Ransomware Nuclei
F5 vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

F5OS vulnerability

On F5OS-A beginning in version 1.2.0 to before 1.3.0 and F5OS-C beginning in version 1.3.0 to before 1.5.0, processing F5OS tenant file names may allow for command injection. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CWE-77Feb 1, 2023
CVSS7.0v3.1EPSS0.443%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

F5OS vulnerability CVE-2022-41835

In F5OS-A version 1.x before 1.1.0 and F5OS-C version 1.x before 1.5.0, excessive file permissions in F5OS allows an authenticated local attacker to execute limited set of commands in a container and impact the F5OS controller.

CWE-269Oct 19, 2022
CVSS7.3v3.1EPSS0.152%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

F5OS CLI vulnerability CVE-2022-41780

In F5OS-A version 1.x before 1.1.0 and F5OS-C version 1.x before 1.4.0, a directory traversal vulnerability exists in an undisclosed location of the F5OS CLI that allows an attacker to read arbitrary files.

CWE-22Oct 19, 2022
CVSS5.5v3.1EPSS0.546%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

On 1.0.x versions prior to 1.0.1, systems running F5OS-A software may expose certain registry ports externally. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CWE-200May 5, 2022
CVSS5.3v3.1EPSS0.738%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX