CVE-2024-22093

When running in appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint on multi-bladed systems. A successful exploit can allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Configurations

No configuration.

History

21 Nov 2024, 08:55

Type Values Removed Values Added
Summary
  • (es) Cuando se ejecuta en modo dispositivo, existe una vulnerabilidad de inyección remota de comandos autenticada en un endpoint iControl REST no revelado en sistemas multiblade. Un exploit exitoso puede permitir al atacante cruzar un límite de seguridad. Nota: Las versiones de software que han llegado al final del soporte técnico (EoTS) no se evalúan
References () https://my.f5.com/manage/s/article/K000137522 - () https://my.f5.com/manage/s/article/K000137522 -

14 Feb 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-14 17:15

Updated : 2024-11-21 08:55


NVD link : CVE-2024-22093

Mitre link : CVE-2024-22093

CVE.ORG link : CVE-2024-22093


JSON object : View

Products Affected

No product.

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')