F5-K000139503: High severity f5 f5os vulnerability
Published May 7, 2025
·Updated
On F5OS, an improper authorization vulnerability exists where remotely authenticated users (LDAP, RADIUS, TACACS+) may be authorized with higher privilege F5OS roles.
Affected Software
2 affected componentsFixes available
F5 F5OS-A=1.5.1
1.8.01.5.2
F5 F5OS-C>=1.6.0<=1.6.2
5
Event History
May 7, 2025
Advisory Published
via F5·12:48 PM
Frequently Asked Questions
1
What is the severity of F5-K000139503?
The severity of F5-K000139503 is classified as critical due to improper authorization allowing higher privilege access.
2
How do I fix F5-K000139503?
To fix F5-K000139503, upgrade to the appropriate patched version of F5OS as recommended in the advisory.
3
Who is affected by F5-K000139503?
F5-K000139503 affects remotely authenticated users utilizing LDAP, RADIUS, and TACACS+ on F5OS.
4
What role escalation occurs in F5-K000139503?
F5-K000139503 allows unauthorized users to be granted higher privilege roles within F5OS.
5
Is there a workaround for F5-K000139503?
Currently, there are no documented workarounds for F5-K000139503 other than applying the recommended updates.