ID

VAR-202210-1308


CVE

CVE-2022-41780


TITLE

F5 F5OS-A and F5OS-C Path traversal vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-202210-1450

DESCRIPTION

In F5OS-A version 1.x before 1.1.0 and F5OS-C version 1.x before 1.4.0, a directory traversal vulnerability exists in an undisclosed location of the F5OS CLI that allows an attacker to read arbitrary files. Both F5 F5OS-A and F5 F5OS-C are products of F5 Company in the United States. F5 F5OS-A is an operating system software. F5 F5OS-C is an operating system software on VELOS hardware

Trust: 0.99

sources: NVD: CVE-2022-41780 // VULHUB: VHN-429544

AFFECTED PRODUCTS

vendor:f5model:f5os-ascope:ltversion:1.1.0

Trust: 1.0

vendor:f5model:f5os-cscope:gtversion:1.1.0

Trust: 1.0

vendor:f5model:f5os-ascope:gteversion:1.0.0

Trust: 1.0

vendor:f5model:f5os-cscope:ltversion:1.4.0

Trust: 1.0

sources: NVD: CVE-2022-41780

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2022-41780
value: MEDIUM

Trust: 1.0

f5sirt@f5.com: CVE-2022-41780
value: MEDIUM

Trust: 1.0

CNNVD: CNNVD-202210-1450
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2022-41780
baseSeverity: MEDIUM
baseScore: 5.5
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 1.8
impactScore: 3.6
version: 3.1

Trust: 2.0

sources: CNNVD: CNNVD-202210-1450 // NVD: CVE-2022-41780 // NVD: CVE-2022-41780

PROBLEMTYPE DATA

problemtype:CWE-22

Trust: 1.1

sources: VULHUB: VHN-429544 // NVD: CVE-2022-41780

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202210-1450

TYPE

path traversal

Trust: 0.6

sources: CNNVD: CNNVD-202210-1450

PATCH

title:F5 F5OS-A and F5OS-C Repair measures for path traversal vulnerabilitiesurl:http://123.124.177.30/web/xxk/bdxqById.tag?id=211820

Trust: 0.6

sources: CNNVD: CNNVD-202210-1450

EXTERNAL IDS

db:NVDid:CVE-2022-41780

Trust: 1.7

db:CNNVDid:CNNVD-202210-1450

Trust: 0.7

db:AUSCERTid:ESB-2022.5235

Trust: 0.6

db:VULHUBid:VHN-429544

Trust: 0.1

sources: VULHUB: VHN-429544 // CNNVD: CNNVD-202210-1450 // NVD: CVE-2022-41780

REFERENCES

url:https://support.f5.com/csp/article/k81701735

Trust: 1.7

url:https://www.auscert.org.au/bulletins/esb-2022.5235

Trust: 0.6

url:https://cxsecurity.com/cveshow/cve-2022-41780/

Trust: 0.6

sources: VULHUB: VHN-429544 // CNNVD: CNNVD-202210-1450 // NVD: CVE-2022-41780

SOURCES

db:VULHUBid:VHN-429544
db:CNNVDid:CNNVD-202210-1450
db:NVDid:CVE-2022-41780

LAST UPDATE DATE

2024-08-14T14:02:19.249000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-429544date:2022-10-24T00:00:00
db:CNNVDid:CNNVD-202210-1450date:2022-10-25T00:00:00
db:NVDid:CVE-2022-41780date:2022-10-24T13:31:06.353

SOURCES RELEASE DATE

db:VULHUBid:VHN-429544date:2022-10-19T00:00:00
db:CNNVDid:CNNVD-202210-1450date:2022-10-19T00:00:00
db:NVDid:CVE-2022-41780date:2022-10-19T22:15:13.060