CVE-2025-60013: F5OS-A FIPS HSM password vulnerability
When a highly-privileged, authenticated attacker attempts to initialize the rSeries FIPS module using a password with special shell metacharacters, arbitrary system commands may be executed, and the FIPS hardware security module (HSM) may fail to initialize. A successful exploit can allow the attacker to cross a security boundary.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60013?
CVE-2025-60013 is considered a medium severity vulnerability due to its potential impact on the initialization of the FIPS hardware security module.
How do I fix CVE-2025-60013?
To fix CVE-2025-60013, avoid using passwords with special shell metacharacters when initializing the rSeries FIPS module.
Which versions of F5OS-A are affected by CVE-2025-60013?
CVE-2025-60013 affects F5OS-A versions from 1.5.1 to 1.8.0 and version 1.8.31.5.4.
What are the potential consequences of CVE-2025-60013?
The potential consequences of CVE-2025-60013 include failure to initialize the FIPS hardware security module, which may impact security operations.
Is there a workaround for CVE-2025-60013?
The only known workaround for CVE-2025-60013 is to refrain from using passwords that contain special shell metacharacters during initialization.