CVE-2023-22657: F5OS vulnerability
Published Feb 1, 2023
·Updated
On F5OS-A beginning in version 1.2.0 to before 1.3.0 and F5OS-C beginning in version 1.3.0 to before 1.5.0, processing F5OS tenant file names may allow for command injection. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
4 affected componentsFixes available
F5 F5OS>=1.2.0<1.3.0
F5 F5OS>=1.3.0<1.5.0
F5 F5OS=1.2.0
1.3.03
F5 F5OS>=1.3.0<=1.3.2
1.5.0
Event History
Feb 1, 2023
Advisory Published
via F5·01:30 PM
CVE Published
via MITRE·05:56 PM
Data Sourced
via MITRE·05:56 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-22657?
The severity of CVE-2023-22657 is high.
2
Which versions of F5OS-A are affected by CVE-2023-22657?
F5OS-A versions 1.2.0 to before 1.3.0 are affected by CVE-2023-22657.
3
Which versions of F5OS-C are affected by CVE-2023-22657?
F5OS-C versions 1.3.0 to before 1.5.0 are affected by CVE-2023-22657.
4
How can an attacker exploit CVE-2023-22657?
An attacker can exploit CVE-2023-22657 by injecting commands into F5OS tenant file names.
5
Is there a fix available for CVE-2023-22657?
Yes, upgrading to F5OS-A version 1.3.0 or later and F5OS-C version 1.5.0 or later will fix CVE-2023-22657.