Skip to main content

Vendor/product archive

f5 / f5os-a CVEs

Beta · best-effort

16 CVEs tagged to f5 / f5os-a1 Critical, 7 High, 8 Medium, 0 Low, 0 Unrated.

CVE-2025-57780

Published Oct 15, 2025

A vulnerability exists in F5OS-A and F5OS-C system that may allow an authenticated attacker with local access to escalate their privileges.  A successful exploit may allow the att…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-53860

Published Oct 15, 2025

A vulnerability exists in F5OS-A software that allows a highly privileged authenticated attacker to access sensitive FIPS hardware security module (HSM) information on F5 rSeries…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-61955

Published Oct 15, 2025

A vulnerability exists in F5OS-A and F5OS-C systems that may allow an authenticated attacker with local access to escalate their privileges.  A successful exploit may allow the at…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-60015

Published Oct 15, 2025

An out-of-bounds write vulnerability exists in F5OS-A and F5OS-C that could lead to memory corruption.  Note: Software versions which have reached End of Technical Support (E…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-60013

Published Oct 15, 2025

When a highly-privileged, authenticated attacker attempts to initialize the rSeries FIPS module using a password with special shell metacharacters, arbitrary system commands may b…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-47150

Published Oct 15, 2025

When SNMP is configured on F5OS Appliance and Chassis systems, undisclosed requests can cause an increase in SNMP memory resource utilization.  Note: Software versions which have…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-46265

Published May 7, 2025

On F5OS, an improper authorization vulnerability exists where remotely authenticated users (LDAP, RADIUS, TACACS+) may be authorized with higher privilege F5OS roles. Note: Softwa…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-36546

Published May 7, 2025

On an F5OS system, if the root user had previously configured the system to allow login via SSH key-based authentication, and then enabled Appliance Mode; access via SSH key-based…

CVSS 9.2 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-24966

Published Feb 14, 2024

When LDAP remote authentication is configured on F5OS, a remote user without an assigned role will be incorrectly authorized.  Note: Software versions which have reached End of Te…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23607

Published Feb 14, 2024

A directory traversal vulnerability exists in the F5OS QKView utility that allows an authenticated attacker to read files outside the QKView directory.  Note: Software versions wh…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-36494

Published Aug 2, 2023

Audit logs on F5OS-A may contain undisclosed sensitive information.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-22657

Published Feb 1, 2023

On F5OS-A beginning in version 1.2.0 to before 1.3.0 and F5OS-C beginning in version 1.3.0 to before 1.5.0, processing F5OS tenant file names may allow for command injection. Not…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-41835

Published Oct 19, 2022

In F5OS-A version 1.x before 1.1.0 and F5OS-C version 1.x before 1.5.0, excessive file permissions in F5OS allows an authenticated local attacker to execute limited set of command…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2022-41780

Published Oct 19, 2022

In F5OS-A version 1.x before 1.1.0 and F5OS-C version 1.x before 1.4.0, a directory traversal vulnerability exists in an undisclosed location of the F5OS CLI that allows an attack…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-25990

Published May 5, 2022

On 1.0.x versions prior to 1.0.1, systems running F5OS-A software may expose certain registry ports externally. Note: Software versions which have reached End of Technical Support…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-16 of 16 CVEsPage 1 of 1