F5-K000154661: Medium severity F5 F5OS-A vulnerability
When a highly-privileged, authenticated attacker attempts to initialize the rSeries FIPS module using a password with special shell metacharacters, arbitrary system commands may be executed, and the FIPS hardware security module (HSM) may fail to initialize. A successful exploit can allow the attacker to cross a security boundary.
Affected Software
Event History
Frequently Asked Questions
What is the severity of F5-K000154661?
The severity of F5-K000154661 is considered medium due to potential impacts on the initialization of the FIPS HSM.
How do I fix F5-K000154661?
To fix F5-K000154661, ensure that the password used for initializing the rSeries FIPS module does not contain special shell metacharacters.
Which versions are affected by F5-K000154661?
F5-K000154661 affects F5OS-A versions 1.8.0 and versions from 1.5.1 to 1.5.3.
What happens if I use special shell metacharacters in F5-K000154661?
Using special shell metacharacters may cause the FIPS hardware security module to fail to initialize properly.
Is there a workaround for F5-K000154661?
The primary workaround for F5-K000154661 is to avoid using passwords with special shell metacharacters during FIPS module initialization.