CVE-2022-41835
published 2022-10-19CVE-2022-41835: In F5OS-A version 1.x before 1.1.0 and F5OS-C version 1.x before 1.5.0, excessive file permissions in F5OS allows an authenticated local attacker to execute…
PriorityP342high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.15%
4.4th percentile
In F5OS-A version 1.x before 1.1.0 and F5OS-C version 1.x before 1.5.0, excessive file permissions in F5OS allows an authenticated local attacker to execute limited set of commands in a container and impact the F5OS controller.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | f5os | — | — |
| f5 | f5os-a | — | — |
| f5 | f5os-a | >= 1.0.0 < 1.1.0 | 1.1.0 |
| f5 | f5os-a | >= 1.x < 1.1.0 | 1.1.0 |
| f5 | f5os-c | < 1.5.0 | 1.5.0 |
| f5 | f5os-c | — | — |
| f5 | f5os-c | >= 1.x < 1.5.0 | 1.5.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-29qx-4rqj-787m: In F5OS-A version 1
ghsa_unreviewed·2022-10-20
CVE-2022-41835 [HIGH] CWE-269 GHSA-29qx-4rqj-787m: In F5OS-A version 1
In F5OS-A version 1.x before 1.1.0 and F5OS-C version 1.x before 1.5.0, excessive file permissions in F5OS allows an authenticated local attacker to execute limited set of commands in a container and impact the F5OS controller.
F5
CVE-2022-41835: In F5OS-A version 1
vendor_f5·2022-10-19·CVSS 7.3
CVE-2022-41835 [HIGH] CWE-269 CVE-2022-41835: In F5OS-A version 1
CVE-2022-41835: In F5OS-A version 1
In F5OS-A version 1.x before 1.1.0 and F5OS-C version 1.x before 1.5.0, excessive file permissions in F5OS allows an authenticated local attacker to execute limited set of commands in a container and impact the F5OS controller.
Affected Products: F5OS, F5OS-A, F5OS-C
Affected Versions: 1.0.0 - 1.1.0; 1.3.0 - 1.5.0
F5 Advisory Articles: K33484483
F5 References: https://support.f5.com/csp/article/K33484483
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-10-19
Published