cbcvebase.
CVE-2023-22657
published 2023-02-01

CVE-2023-22657: On F5OS-A beginning in version 1.2.0 to before 1.3.0 and F5OS-C beginning in version 1.3.0 to before 1.5.0, processing F5OS tenant file names may allow for…

PriorityP338high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.44%
35.7th percentile
On F5OS-A beginning in version 1.2.0 to before 1.3.0 and F5OS-C beginning in version 1.3.0 to before 1.5.0, processing F5OS tenant file names may allow for command injection. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected

5 ranges
VendorProductVersion rangeFixed in
f5f5os
f5f5os-a
f5f5os-a>= 1.2.0 < 1.3.01.3.0
f5f5os-c
f5f5os-c>= 1.3.0 < 1.5.01.5.0
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.