CVE-2024-23607: F5OS QKView utility vulnerability
A directory traversal vulnerability exists in the F5OS QKView utility that allows an authenticated attacker to read files outside the QKView directory.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
F5 F5OSto a version that resolves this vulnerability.Fixed in 1.4.0 - Upgrade
Upgrade
F5 F5OSto a version that resolves this vulnerability.Fixed in 1.6.0
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23607?
CVE-2024-23607 is classified as a high severity vulnerability due to its potential to allow authenticated attackers to access sensitive files.
How do I fix CVE-2024-23607?
To resolve CVE-2024-23607, upgrade to F5OS-A version 1.4.0 or later, or F5OS-C version 1.6.0 or later.
What versions are affected by CVE-2024-23607?
CVE-2024-23607 affects F5OS-A versions 1.3.0 to 1.4.0 and F5OS-C versions 1.3.0 to 1.6.0.
Can CVE-2024-23607 be exploited remotely?
Although CVE-2024-23607 requires authentication, it can still be exploited remotely by authenticated users.
What impact does CVE-2024-23607 have on system security?
CVE-2024-23607 allows attackers to read files outside of the intended directory, potentially exposing sensitive information.