cbcvebase.
CVE-2022-41835
published 2022-10-19

CVE-2022-41835: In F5OS-A version 1.x before 1.1.0 and F5OS-C version 1.x before 1.5.0, excessive file permissions in F5OS allows an authenticated local attacker to execute…

PriorityP342high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.15%
4.4th percentile
In F5OS-A version 1.x before 1.1.0 and F5OS-C version 1.x before 1.5.0, excessive file permissions in F5OS allows an authenticated local attacker to execute limited set of commands in a container and impact the F5OS controller.

Affected

7 ranges
VendorProductVersion rangeFixed in
f5f5os
f5f5os-a
f5f5os-a>= 1.0.0 < 1.1.01.1.0
f5f5os-a>= 1.x < 1.1.01.1.0
f5f5os-c< 1.5.01.5.0
f5f5os-c
f5f5os-c>= 1.x < 1.5.01.5.0
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.