CVE-2025-60013
published 2025-10-15CVE-2025-60013: When a highly-privileged, authenticated attacker attempts to initialize the rSeries FIPS module using a password with special shell metacharacters, arbitrary…
PriorityP423medium4.6CVSS 3.1
AVLACLPRHUINSCCLILAN
EPSS
0.17%
6.6th percentile
When a highly-privileged, authenticated attacker attempts to initialize the rSeries FIPS module using a password with special shell metacharacters, arbitrary system commands may be executed, and the FIPS hardware security module (HSM) may fail to initialize. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | f5os-a | — | — |
| f5 | f5os-a | — | — |
| f5 | f5os-a | >= 1.5.1 < 1.5.4 | 1.5.4 |
| f5 | f5os_appliance | >= 1.5.0 < 1.5.4 | 1.5.4 |
| f5 | f5os_appliance | >= 1.8.0 < 1.8.3 | 1.8.3 |
CVSS provenance
nvdv3.14.6MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
nvdv4.04.6MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache Tomcat Vulnerable to Relative Path Traversal
ghsa·2025-10-27
CVE-2025-55752 [HIGH] CWE-23 Apache Tomcat Vulnerable to Relative Path Traversal
Apache Tomcat Vulnerable to Relative Path Traversal
The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This introduced the possibility that, for rewrite rules that rewrite query parameters to the URL, an attacker could manipulate the request URI to bypass security constraints including the protection for /WEB-INF/ and /META-INF/. If PUT requests were also enabled then malicious files could be uploaded leading to remote code execution. PUT requests are normally limited to trusted users and it is considered unlikely that PUT requests would be enabled in conjunction with a rewrite that manipulated the URI.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.0.0.M11 through 9.0.108.
GHSA
GHSA-g34m-cm8j-m5gg: When a user attempts to initialize the rSeries FIPS module using a password with special shell metacharacters, the FIPS hardware security module (HSM)
ghsa_unreviewed·2025-10-15
CVE-2025-60013 [MEDIUM] CWE-78 GHSA-g34m-cm8j-m5gg: When a user attempts to initialize the rSeries FIPS module using a password with special shell metacharacters, the FIPS hardware security module (HSM)
When a user attempts to initialize the rSeries FIPS module using a password with special shell metacharacters, the FIPS hardware security module (HSM) may fail to initialize. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
F5
CVE-2025-60013: When a highly-privileged, authenticated attacker attempts to initialize the rSeries FIPS module using a password with...
vendor_f5·2025-10-15·CVSS 4.6
CVE-2025-60013 [MEDIUM] CWE-78 CVE-2025-60013: When a highly-privileged, authenticated attacker attempts to initialize the rSeries FIPS module using a password with...
CVE-2025-60013: When a highly-privileged, authenticated attacker attempts to initialize the rSeries FIPS module using a password with...
When a highly-privileged, authenticated attacker attempts to initialize the rSeries FIPS module using a password with special shell metacharacters, arbitrary system commands may be executed, and the FIPS hardware security module (HSM) may fail to initialize. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Products: F5OS-A
Affected Versions: 1.5.1 - 1.5.4; 1.8.0
F5 Advisory Articles: K000154661
F5 References: https://my.f5.com/manage/s/article/K000154661
No detection rules found.
No public exploits indexed.
2025-10-15
Published