F5-K000148587: Command Injection
Published Feb 5, 2025
·Updated
A command injection vulnerability exists in iControl REST and the BIG-IP TMOS Shell (tmsh), which may allow an authenticated attacker to execute arbitrary system commands.
Affected Software
3 affected componentsFixes available
F5 BIG-IP>=17.1.0<=17.1.2
17.1.2.1
F5 BIG-IP>=16.1.0<=16.1.5
16.1.5.2
F5 BIG-IP>=15.1.0<=15.1.10
15.1.10.6
Event History
Feb 5, 2025
Advisory Published
via F5·02:20 PM
Frequently Asked Questions
1
What is the severity of F5-K000148587?
The severity of F5-K000148587 is considered high due to the potential for arbitrary command execution.
2
How do I fix F5-K000148587?
To fix F5-K000148587, upgrade to the recommended versions of BIG-IP as outlined in the advisory.
3
Who is affected by F5-K000148587?
Organizations using specific versions of F5 BIG-IP, particularly those between 15.1.0 and 15.1.10, 16.1.0 and 16.1.5, or 17.1.0 and 17.1.2, are affected by F5-K000148587.
4
What could an attacker achieve with F5-K000148587?
An attacker exploiting F5-K000148587 could execute arbitrary system commands, leading to potential system compromise.
5
What are the products involved in F5-K000148587?
The products involved in F5-K000148587 are F5 BIG-IP versions 15.1.x, 16.1.x, and 17.1.x.