QID 378033
QID 378033: F5OS vulnerability CVE-2022-41835 (K33484483)
Excessive file permissions in F5OS allow an authenticated local attacker to execute a limited set of commands in a container and impact the F5OS controller. (CVE-2022-41835)
Vulnerable Component: BIG-IP F5OS
Affected Versions:
1.0.0 - 1.0.1
1.3.0 - 1.3.2
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
An authenticated low-privileged attacker with CLI access can exploit this vulnerability locally by including crafted arguments to a specific command. A successful exploit allows the attacker to escalate privileges and cross a security boundary.
Solution
For more information about patch details please refer to K33484483
Vendor References
- K33484483 -
my.f5.com/manage/s/article/K33484483
CVEs related to QID 378033
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K33484483 |
|