CVE-2025-43878
8.3
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow more
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: f5sirt@f5.com (Secondary)
Description
When running in Appliance mode, an authenticated attacker assigned the Administrator or Resource Administrator role may be able to bypass Appliance mode restrictions utilizing system diagnostics tcpdump command utility on a F5OS-C/A system.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected (2)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.5.1 to 1.8.0 | |
| From 1.6.0 to 1.6.2 |
| Running on/with | Platform Versions |
|---|---|
F5 R10600 | All versions |
F5 R10800 | All versions |
F5 R10900 | All versions |
F5 R12600 Ds | All versions |
F5 R12800 Ds | All versions |
F5 R12900 Ds | All versions |
F5 R5600 | All versions |
F5 R5800 | All versions |
F5 R5900 | All versions |
F5 Velos Cx1610 | All versions |
F5 Velos Cx410 | All versions |
Related CWEs
CWE-1286
Improper Validation of Syntactic Correctness of Input
The product receives input that is expected to be well-formed - i.e., to comply with a certain syntax - but it does not validate or incorrectly validates that the input complies with the syntax.
CWE-149
Improper Neutralization of Quoting Syntax
Quotes injected into a product can be used to compromise a system. As data are parsed, an injected/absent/duplicate/malformed use of quotes may cause the process to take unexpected actions.
References (1)
Timeline
No history available yet.