CVE-2025-43878

CWE-149CWE-12864 documents4 sources
Severity
8.3HIGH
EPSS
0.1%
top 66.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 7
Latest updateMay 8

Description

When running in Appliance mode, an authenticated attacker assigned the Administrator or Resource Administrator role may be able to bypass Appliance mode restrictions utilizing system diagnostics tcpdump command utility on a F5OS-C/A system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Packages4 packages

CVEListV5f5/f5os_-_appliance1.5.11.8.0
NVDf5/f5os-a1.5.11.8.0
CVEListV5f5/f5os_-_chassis1.6.01.8.0
NVDf5/f5os-c1.6.01.6.2

🔴Vulnerability Details

2
GHSA
GHSA-jv2x-vg3f-2535: When running in Appliance mode, an authenticated attacker assigned the Administrator or Resource Administrator role may be able to bypass Appliance mo2025-05-08
CVEList
F5OS-A/C CLI vulnerability2025-05-07

📋Vendor Advisories

1
F5
CVE-2025-43878: When running in Appliance mode, an authenticated attacker assigned the Administrator or Resource Administrator role m...2025-05-07
CVE-2025-43878 (HIGH CVSS 8.3) | When running in Appliance mode | cvebase.io