CVE-2025-43878CWE-1286CWE-149

F5OS-A/C CLI vulnerability

High · published May 7, 2025

CVSS v4.0
8.3
EPSS
0%
Percentile
5.9
In the wild
Unconfirmed
What it is

When running in Appliance mode, an authenticated attacker assigned the Administrator or Resource Administrator role may be able to bypass Appliance mode restrictions utilizing system diagnostics tcpdump command utility on a F5OS-C/A system.

Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

The record
Technical detail
CVSS v4.0
8.3 · HIGH
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS
0.00165 · 5.9th percentile
Weaknesses
CWE-1286 · Improper Validation of Syntactic Correctness of Input; CWE-149 · Improper Neutralization of Quoting Syntax
Published
2025-05-07T22:04Z
EPSS history
Timeline
  • 07 MAY 22:04Z
    F5OS-A/C CLI vulnerability
    cvelistv5