F5OS-A/C Command Injection via Tenant File Names (v1.2.x-1.3.x / v1.3.x-1.5.x)
CVE-2023-22657 Published on February 1, 2023
F5OS vulnerability
On F5OS-A beginning in version 1.2.0 to before 1.3.0 and F5OS-C beginning in version 1.3.0 to before 1.5.0, processing F5OS tenant file names may allow for command injection. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Vulnerability Analysis
CVE-2023-22657 can be exploited with local system access, requires user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Weakness Type
What is a Command Injection Vulnerability?
The software constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CVE-2023-22657 has been classified to as a Command Injection vulnerability or weakness.
Products Associated with CVE-2023-22657
stack.watch emails you whenever new vulnerabilities are published in F5 Networks F5os C or F5 Networks F5os A. Just hit a watch button to start following.
Affected Versions
F5OS-A:- Version 1.2.0 and below 1.3.0 is affected.
- Version 1.3.0 and below 1.5.0 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.