CVE-2022-41780: F5OS CLI vulnerability CVE-2022-41780
In F5OS-A version 1.x before 1.1.0 and F5OS-C version 1.x before 1.4.0, a directory traversal vulnerability exists in an undisclosed location of the F5OS CLI that allows an attacker to read arbitrary files.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
F5OS-Ato a version that resolves this vulnerability.Fixed in 1.1.0 - Upgrade
Upgrade
F5OS-Cto a version that resolves this vulnerability.Fixed in 1.4.0
Event History
Frequently Asked Questions
What is CVE-2022-41780?
CVE-2022-41780 is a directory traversal vulnerability in F5OS-A version 1.x before 1.1.0 and F5OS-C version 1.x before 1.4.0 that allows an attacker to read arbitrary files.
How severe is CVE-2022-41780?
CVE-2022-41780 has a severity rating of 5.5 (Medium).
How does CVE-2022-41780 affect F5OS-A and F5OS-C?
CVE-2022-41780 affects F5OS-A version 1.x before 1.1.0 and F5OS-C version 1.x before 1.4.0.
How can an attacker exploit CVE-2022-41780?
An attacker can exploit CVE-2022-41780 by performing a directory traversal attack on the F5OS CLI to read arbitrary files.
Is there a fix available for CVE-2022-41780?
Yes, a fix is available for CVE-2022-41780. Update to F5OS-A version 1.1.0 or later, or F5OS-C version 1.4.0 or later.