Home
HIGH: 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HHIGH: 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NDefault status
unknown
1.7.0 (custom) before 1.8.0
affected
1.5.1 (custom) before 1.5.2
affected
Default status
unknown
1.6.0 (custom) before 1.8.0
affected
Description
On F5OS, an improper authorization vulnerability exists where remotely authenticated users (LDAP, RADIUS, TACACS+) may be authorized with higher privilege F5OS roles. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Problem types
CWE-863 Incorrect Authorization
Product status
1.7.0 (custom) before 1.8.0
1.5.1 (custom) before 1.5.2
1.6.0 (custom) before 1.8.0
Credits
F5
References
my.f5.com/manage/s/article/K000139503