PT-2022-26089 · F5 · F5Os-C+1

Published

2022-10-19

·

Updated

2022-10-24

·

CVE-2022-41835

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions F5OS-A versions 1.x before 1.1.0 F5OS-C versions 1.x before 1.5.0
Description The issue is related to excessive file permissions in F5OS, allowing an authenticated local attacker to execute a limited set of commands in a container and impact the F5OS controller.
Recommendations For F5OS-A versions 1.x before 1.1.0, update to version 1.1.0 or later. For F5OS-C versions 1.x before 1.5.0, update to version 1.5.0 or later.

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2022-41835

Affected Products

F5Os-A
F5Os-C