F5-K000148591: Command Injection
When running in Appliance mode, a command injection vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with administrator role privileges to execute arbitrary system commands. A successful exploit can allow the attacker to cross a security boundary.
Affected Software
Event History
Frequently Asked Questions
What is the severity of F5-K000148591?
The severity of F5-K000148591 is high due to its potential for command injection by authenticated attackers.
How do I fix F5-K000148591?
To fix F5-K000148591, upgrade to the recommended patched version of F5 BIG-IP or BIG-IQ as specified in the advisory.
What products are affected by F5-K000148591?
F5-K000148591 affects F5 BIG-IP and BIG-IQ Centralized Management running specific vulnerable versions.
Who can exploit F5-K000148591?
Only authenticated attackers with administrator role privileges can exploit F5-K000148591.
What type of vulnerability is F5-K000148591?
F5-K000148591 is a command injection vulnerability in the iControl REST and BIG-IP TMOS Shell.