F5

F5os-a

8 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.26%
  • Veröffentlicht 14.02.2024 17:15:15
  • Zuletzt bearbeitet 24.01.2025 16:03:35

When LDAP remote authentication is configured on F5OS, a remote user without an assigned role will be incorrectly authorized.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • EPSS 0.17%
  • Veröffentlicht 14.02.2024 17:15:13
  • Zuletzt bearbeitet 24.01.2025 16:03:56

A directory traversal vulnerability exists in the F5OS QKView utility that allows an authenticated attacker to read files outside the QKView directory.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • EPSS 0.08%
  • Veröffentlicht 02.08.2023 16:15:10
  • Zuletzt bearbeitet 15.04.2025 14:07:39

Audit logs on F5OS-A may contain undisclosed sensitive information.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • EPSS 0.17%
  • Veröffentlicht 01.02.2023 18:15:11
  • Zuletzt bearbeitet 21.11.2024 07:45:08

On F5OS-A beginning in version 1.2.0 to before 1.3.0 and F5OS-C beginning in version 1.3.0 to before 1.5.0, processing F5OS tenant file names may allow for command injection. Note: Software versions which have reached End of Technical Support (EoTS)...

  • EPSS 0.2%
  • Veröffentlicht 19.10.2022 22:15:13
  • Zuletzt bearbeitet 21.11.2024 07:23:49

In F5OS-A version 1.x before 1.1.0 and F5OS-C version 1.x before 1.4.0, a directory traversal vulnerability exists in an undisclosed location of the F5OS CLI that allows an attacker to read arbitrary files.

  • EPSS 0.05%
  • Veröffentlicht 19.10.2022 22:15:13
  • Zuletzt bearbeitet 21.11.2024 07:23:54

In F5OS-A version 1.x before 1.1.0 and F5OS-C version 1.x before 1.5.0, excessive file permissions in F5OS allows an authenticated local attacker to execute limited set of commands in a container and impact the F5OS controller.

  • EPSS 0.23%
  • Veröffentlicht 05.05.2022 17:15:11
  • Zuletzt bearbeitet 21.11.2024 06:53:17

On 1.0.x versions prior to 1.0.1, systems running F5OS-A software may expose certain registry ports externally. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

Exploit
  • EPSS 14.68%
  • Veröffentlicht 11.11.2021 19:15:07
  • Zuletzt bearbeitet 22.08.2025 10:33:16

The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ate...