ID

VAR-202210-1306


CVE

CVE-2022-41835


TITLE

F5 F5OS-A Security hole

Trust: 0.6

sources: CNNVD: CNNVD-202210-1454

DESCRIPTION

In F5OS-A version 1.x before 1.1.0 and F5OS-C version 1.x before 1.5.0, excessive file permissions in F5OS allows an authenticated local attacker to execute limited set of commands in a container and impact the F5OS controller. F5 F5OS-A is an operating system software produced by F5 Corporation in the United States

Trust: 0.99

sources: NVD: CVE-2022-41835 // VULHUB: VHN-429540

AFFECTED PRODUCTS

vendor:f5model:f5os-ascope:ltversion:1.1.0

Trust: 1.0

vendor:f5model:f5os-ascope:gteversion:1.0.0

Trust: 1.0

vendor:f5model:f5os-cscope:gtversion:1.3.0

Trust: 1.0

vendor:f5model:f5os-cscope:ltversion:1.5.0

Trust: 1.0

sources: NVD: CVE-2022-41835

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2022-41835
value: HIGH

Trust: 1.0

f5sirt@f5.com: CVE-2022-41835
value: HIGH

Trust: 1.0

CNNVD: CNNVD-202210-1454
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2022-41835
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: CHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.0
impactScore: 6.0
version: 3.1

Trust: 1.0

f5sirt@f5.com: CVE-2022-41835
baseSeverity: HIGH
baseScore: 7.3
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: CHANGED
confidentialityImpact: NONE
integrityImpact: LOW
availabilityImpact: HIGH
exploitabilityScore: 2.0
impactScore: 4.7
version: 3.1

Trust: 1.0

sources: CNNVD: CNNVD-202210-1454 // NVD: CVE-2022-41835 // NVD: CVE-2022-41835

PROBLEMTYPE DATA

problemtype:CWE-269

Trust: 1.1

sources: VULHUB: VHN-429540 // NVD: CVE-2022-41835

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202210-1454

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202210-1454

PATCH

title:F5 F5OS-A Security vulnerabilitiesurl:http://123.124.177.30/web/xxk/bdxqById.tag?id=211325

Trust: 0.6

sources: CNNVD: CNNVD-202210-1454

EXTERNAL IDS

db:NVDid:CVE-2022-41835

Trust: 1.7

db:CNNVDid:CNNVD-202210-1454

Trust: 0.7

db:VULHUBid:VHN-429540

Trust: 0.1

sources: VULHUB: VHN-429540 // CNNVD: CNNVD-202210-1454 // NVD: CVE-2022-41835

REFERENCES

url:https://support.f5.com/csp/article/k33484483

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2022-41835

Trust: 0.6

url:https://cxsecurity.com/cveshow/cve-2022-41835/

Trust: 0.6

sources: VULHUB: VHN-429540 // CNNVD: CNNVD-202210-1454 // NVD: CVE-2022-41835

SOURCES

db:VULHUBid:VHN-429540
db:CNNVDid:CNNVD-202210-1454
db:NVDid:CVE-2022-41835

LAST UPDATE DATE

2024-08-14T15:42:11.630000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-429540date:2022-10-24T00:00:00
db:CNNVDid:CNNVD-202210-1454date:2022-10-25T00:00:00
db:NVDid:CVE-2022-41835date:2022-10-24T15:51:49.297

SOURCES RELEASE DATE

db:VULHUBid:VHN-429540date:2022-10-19T00:00:00
db:CNNVDid:CNNVD-202210-1454date:2022-10-19T00:00:00
db:NVDid:CVE-2022-41835date:2022-10-19T22:15:13.470