First published: Wed Feb 14 2024(Updated: )
A directory traversal vulnerability exists in the F5OS QKView utility that allows an authenticated attacker to read files outside the QKView directory. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 F5OS | >=1.3.0<=1.3.2 | 1.4.0 |
F5 F5OS | >=1.3.0<=1.5.1 | 1.6.0 |
F5 F5OS | >=1.3.0<1.4.0 | |
F5 F5OS | >=1.3.0<1.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-23607 is classified as a high severity vulnerability due to its potential to allow authenticated attackers to access sensitive files.
To resolve CVE-2024-23607, upgrade to F5OS-A version 1.4.0 or later, or F5OS-C version 1.6.0 or later.
CVE-2024-23607 affects F5OS-A versions 1.3.0 to 1.4.0 and F5OS-C versions 1.3.0 to 1.6.0.
Although CVE-2024-23607 requires authentication, it can still be exploited remotely by authenticated users.
CVE-2024-23607 allows attackers to read files outside of the intended directory, potentially exposing sensitive information.