First published: Wed Feb 05 2025(Updated: )
A command injection vulnerability exists in iControl REST and the BIG-IP TMOS Shell (tmsh), which may allow an authenticated attacker to execute arbitrary system commands.
Affected Software | Affected Version | How to fix |
---|---|---|
F5 BIG-IP | >=17.1.0<=17.1.2 | 17.1.2.1 |
F5 BIG-IP | >=16.1.0<=16.1.5 | 16.1.5.2 |
F5 BIG-IP | >=15.1.0<=15.1.10 | 15.1.10.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of F5-K000148587 is considered high due to the potential for arbitrary command execution.
To fix F5-K000148587, upgrade to the recommended versions of BIG-IP as outlined in the advisory.
Organizations using specific versions of F5 BIG-IP, particularly those between 15.1.0 and 15.1.10, 16.1.0 and 16.1.5, or 17.1.0 and 17.1.2, are affected by F5-K000148587.
An attacker exploiting F5-K000148587 could execute arbitrary system commands, leading to potential system compromise.
The products involved in F5-K000148587 are F5 BIG-IP versions 15.1.x, 16.1.x, and 17.1.x.