CVE-2025-43878: F5OS-A/C CLI vulnerability
When running in appliance mode, an authenticated attacker assigned the Administrator or Resource Administrator role may be able to bypass Appliance mode restrictions utilizing system diagnostics tcpdump command utility on a F5OS-A/C system.
Other sources
When running in Appliance mode, an authenticated attacker assigned the Administrator or Resource Administrator role may be able to bypass Appliance mode restrictions utilizing system diagnostics tcpdump command utility on a F5OS-C/A system.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43878?
CVE-2025-43878 is considered a high severity vulnerability due to the potential for administrative privilege escalation.
How do I fix CVE-2025-43878?
To mitigate CVE-2025-43878, upgrade to F5OS-A version 1.8.0 or later for affected F5OS-A systems, and F5OS-C version 1.8.0 or later for affected F5OS-C systems.
Who is impacted by CVE-2025-43878?
CVE-2025-43878 impacts systems running F5OS-A and F5OS-C versions 1.5.1 to 1.5.3 and 1.6.0 to 1.6.2 respectively.
What actions can an attacker take with CVE-2025-43878?
An authenticated attacker assigned the Administrator role can utilize the tcpdump command to bypass Appliance mode restrictions.
Is CVE-2025-43878 remotely exploitable?
CVE-2025-43878 is not remotely exploitable as it requires authentication and specific role assignments to exploit.