CVE-2023-45226

Severity
7.4HIGH
EPSS
0.6%
top 31.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 10

Description

The BIG-IP SPK TMM (Traffic Management Module) f5-debug-sidecar and f5-debug-sshd containers contains hardcoded credentials that may allow an attacker with the ability to intercept traffic to impersonate the SPK Secure Shell (SSH) server on those containers. This is only exposed when ssh debug is enabled. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 2.2 | Impact: 5.2

Affected Packages2 packages

CVEListV5f5/big-ip_next_spk1.5.01.6.0

🔴Vulnerability Details

2
CVEList
BIG-IP Next SPK SSH vulnerability2023-10-10
GHSA
GHSA-6vq9-584m-2q8f: The BIG-IP SPK TMM (Traffic Management Module) f5-debug-sidecar and f5-debug-sshd containers contains hardcoded credentials that may allow an attacker2023-10-10

📋Vendor Advisories

1
F5
CVE-2023-45226: The BIG-IP SPK TMM (Traffic Management Module) f5-debug-sidecar and f5-debug-sshd containers contains hardcoded crede...2023-10-10