CVE-2023-45226

CVSS 3.1 Score 7.4 of 10 (high)

Details

Published Oct 10, 2023
Updated: Oct 18, 2023
CWE ID 798

Summary

CVE-2023-45226 is a vulnerability affecting the BIG-IP SPK TMM (Traffic Management Module) f5-debug-sidecar and f5-debug-sshd containers. The issue involves hardcoded credentials, which can be exploited by an attacker intercepting traffic to impersonate the SPK Secure Shell (SSH) server on these containers. However, for this vulnerability to be exploited, the ssh debug mode must be enabled. Importantly, software versions that have reached End of Technical Support (EoTS) are not evaluated in relation to this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share