2025年2月14日星期五

F5 Products Remote Code Execution Vulnerability

F5 Products Remote Code Execution Vulnerability

Release Date: 13 Feb 2025

RISK: High Risk

TYPE: Operating Systems - Networks OS

A vulnerability was identified in F5 Products. A remote attacker could exploit this vulnerability to trigger remote code execution on the targeted system.

 

Note:

No patch is currently available for CVE-2024-9287 of the affected products. Hence, the risk level is rated as High Risk.


Impact

  • Remote Code Execution

System / Technologies affected

BIG-IP Next CNF

  • 1.1.0 - 1.4.0

 

BIG-IP Next SPK

  • 1.7.0 - 1.9.2

Solutions

Workaround:

Mitigate the vulnerability of attacks by following workaround:

 

  1. Do not create and use custom Python scripts using the vulnerable venv module

 

Please visit the vendor web-site for more details.

 

Apply workarounds issued by the vendor:

 

 


    Vulnerability Identifier


    Source


    Related Link

    沒有留言:

    發佈留言

    思科產品多個漏洞

    思科產品多個漏洞 於思科產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況,資料篡改及繞過保安限制。 影響 阻斷服務 繞過保安限制 篡改 受影響之系統或技術 Cisco IOS Cisco IOS XE 請參考供應商發佈的連結以了解受影響的版本: https:...