Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-22657


On F5OS-A beginning in version 1.2.0 to before 1.3.0 and F5OS-C beginning in version 1.3.0 to before 1.5.0, processing F5OS tenant file names may allow for command injection. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.


Published

2023-02-01T18:15:11.600

Last Modified

2024-11-21T07:45:08.870

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.0 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-77
  • Type: Primary
    CWE-77

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System f5 f5os-a < 1.3.0 Yes
Operating System f5 f5os-c < 1.5.0 Yes

References