vulnerability

F5 Networks: CVE-2023-45226: K000135874: BIG-IP Next SPK SSH vulnerability CVE-2023-45226

Severity
9
CVSS
(AV:N/AC:M/Au:N/C:C/I:C/A:N)
Published
Oct 10, 2023
Added
Jan 9, 2024
Modified
Jan 28, 2025

Description


The BIG-IP SPK TMM (Traffic Management Module) f5-debug-sidecar and f5-debug-sshd containers contains hardcoded credentials that may allow an attacker with the ability to intercept traffic to impersonate the SPK Secure Shell (SSH) server on those containers. This is only exposed when ssh debug is enabled.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

Solution

f5-big-ip-upgrade-latest
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.