F5 Vulnerabilities and Affected Products
Vulnerabilities associated with F5OS-A.
Products
Clear product- BIG-IP257 vulnerabilities
- NGINX Plus31 vulnerabilities
- NGINX Open Source29 vulnerabilities
- BIG-IP Next CNF26 vulnerabilities
- BIG-IP Next SPK23 vulnerabilities
- BIG-IQ19 vulnerabilities
- BIG-IP Next for Kubernetes13 vulnerabilities
- BIG-IP APM12 vulnerabilities
- F5OS - Appliance12 vulnerabilities
- BIG-IP Edge Client11 vulnerabilities
- F5OS - Chassis10 vulnerabilities
- BIG-IP Next Central Manager9 vulnerabilities
- BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, FPS, GTM, Link Controller, PEM, WebAccelerator)8 vulnerabilities
- BIG-IQ Centralized Management7 vulnerabilities
- big-ip_next_central_manager6 vulnerabilities
- nginx6 vulnerabilities
- NGINX Ingress Controller5 vulnerabilities
- NGINX Instance Manager5 vulnerabilities
- nginx_plus5 vulnerabilities
- BIG-IP Guided Configuration (GC)4 vulnerabilities
- BIG-IP Next4 vulnerabilities
- F5OS-A4 vulnerabilities
- BIG-IP Advanced WAF & ASM3 vulnerabilities
- BIG-IP AFM3 vulnerabilities
- BIG-IP APM Clients3 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2023-22657HIGH | F5OS vulnerabilityOn F5OS-A beginning in version 1.2.0 to before 1.3.0 and F5OS-C beginning in version 1.3.0 to before 1.5.0, processing F5OS tenant file names may allow for command injection. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. CWE-77Feb 1, 2023 | CVSS7.0v3.1 | EPSS0.443% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-41835HIGH | F5OS vulnerability CVE-2022-41835In F5OS-A version 1.x before 1.1.0 and F5OS-C version 1.x before 1.5.0, excessive file permissions in F5OS allows an authenticated local attacker to execute limited set of commands in a container and impact the F5OS controller. CWE-269Oct 19, 2022 | CVSS7.3v3.1 | EPSS0.152% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-41780MEDIUM | F5OS CLI vulnerability CVE-2022-41780In F5OS-A version 1.x before 1.1.0 and F5OS-C version 1.x before 1.4.0, a directory traversal vulnerability exists in an undisclosed location of the F5OS CLI that allows an attacker to read arbitrary files. CWE-22Oct 19, 2022 | CVSS5.5v3.1 | EPSS0.546% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-25990MEDIUM | On 1.0.x versions prior to 1.0.1, systems running F5OS-A software may expose certain registry ports externally. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated CWE-200May 5, 2022 | CVSS5.3v3.1 | EPSS0.738% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |